Relying on client-side scripting as a positive security mechanism has been generally regarded as not a particularly smart idea—after all, it can be bypassed the attacker. Unfortunately this is an outdated view—with a little understanding, client-side code can be turned into an effective weapon capable of combating the latest generation of application assessment tools and most automated attack vectors.