> I was able to actually put a block script into a jpeg right at the
> beginning, and it executed.  Unfortunately, the rest of the jpeg didn't
> render as an image (which was my hope), it merely displayed 
> as hex which was pretty ugly.

What about a redirect to an image with your script? at the end? That
is what I do with DMS that show docs as HTML hyperlink

hyperlink-->js (renamed to something else so it will execute instead
of prompt download dialogue)-->js script runs, redirect to real .doc

> Arian, what I have NOT been able to do is just display the 
> images in an HTML file ie < Img src= script . jpg > and have it work...

Yeah, I have a couple suspicions about what may have happened to lead
me to think I could do this. One of which is lack of intelligence. :)

I had four hours to pen test an app, and I know you're familiar with some
of the strange scenarios one can get, and the results led me to make some
unwarranted assumptions that I clearly need to go back and validate.

(I am thinking now that one of my test scripts wound up somewhere else
on the same pages I was attempting to insert into images, and that I
concluded it was the script in the img src executing; either way, clearly
I need to post working examples with my musings or shutup...)

I am usually pretty rigorous about verification, but every now and then
one has to go and completely miss the boat on something, Heh, I should
do that more in private,

