iframe to get untampered functions [Fragment Verison]

Go to 直接DOM挿入 Verison
// (1) まずは iframe をつくる。
const el_iframe=document.createElement("iframe");

// (2) これがtamperされてなければ、contentDocument は null のはずである。
console.log('el_iframe.contentDocument===null',el_iframe.contentDocument===null);

// (3) 表示は off にしておく。
el_iframe.style.display="none";

// (4) fragment をつくって、その中に iframe をいれておく。
const fragment=new DocumentFragment();
fragment.appendChild(el_iframe);

// (5) 次に fragment ごと DOM にいれる。
document.body.appendChild(fragment);

// (6) これで contentDocument は null ではなくなるはずである。
console.log('el_iframe.contentDocument===null',el_iframe.contentDocument===null);

// (7) iframe の document object をキープしておく。
const doc=el_iframe.contentDocument;

// (8) iframe を DOM から削除する。
el_iframe.remove();

// (9) この doc.write に document を bind する。
const wfunc=doc.write.bind(document):

// (10) 最後にこの関数を用いて、write を行う。
wfunc("This is ouputted by wfunc!");


ページの document を tamper されていたとしても、このように、iframe の document を使用するれば、 tampering を迂回することができる。しかし iframe の document は tamper されていないのだろうか? (1) の時点では、tamper されていない。なぜなら、iframe を create しただけでは、iframe の document はまだ null だからである。document なしでは、tamper しようがない。問題は(5)である。この document.body.appendChild がニセものであると、document は tamper されてしまう。 そのなれば、(9)の doc.write はすでにtamperされている関数ということになってしまう。 これが、現時点で存在する弱点である。