Attack: escape to Function() and read document.cookie
Controls: benign Object methods must still work