With javascript malware coders are telling us that they can do nearly everything and that it should be blocked in the browser if you want to start surfing the safe way. That is quite difficult because javascript has been built in thousands of websites and surfing with toggling javascript on/off seems quite time-consuming also. Analysing javascript for malicious scripts is also difficult and may slow internetsurfing down to an unacceptable speed.

here is one proof

If you are behind a firewall you shouldn't see the ip address of your machine with this test http://www.proxyblind.org/javaip.shtml  (only java)

but the chances are great that you will when the tool uses javascript to get the real ip address from your machine with this http://www.proxyblind.org/javaipp.shtml

