3 ms·
> The newly opened tab can then change the window.opener.location to some phishing page. This is true, and is a vulnerability I have been looking at for a whil
by nmjohn 10y ago
> The newly opened tab can then change the window.opener.location to some phishing page.
This is true, and is a vulnerability I have been looking at for a while now, though I've not actually seen it exploited yet in the real world. For anyone interested, there are some pretty interesting exploits involving pages where an auth token is in the querystring and thus sent in the referer field by the browser. Also, consider what happens when you use an alert() in javascript to yank context back to the now attacker controlled tab...
> Or execute some JavaScript on the opener-page on your behalf…
Not true, this implies the "attacker" can run javascript in the context of the original page. They can only run javascript after redirecting the original page to one they control, so it's not like they can run code on the facebook.com domain, which would be a _huge_ exploit.
- eridius 10y agoWhat happens if they change `window.opener.location` to a javascript: URI? I'm assuming (well, hoping) it fails to work, but it would be nice to have that confirmed.
- nmjohn 10y agoAt least in chrome, you get the warning: > Blocked a frame with origin "https://www.google.com" https://www.google.com" from accessing a frame with origin "https://news.ycombinator.com" https://news.ycombinator.com". Protocols, domains, and ports must match. When executing window.opener.location = 'javascript:alert(1);'
- bzbarsky 10y agoIf you do that cross-origin, the script will not be executed, both per spec and in browsers. That would be a pretty wide-gaping security hole if it worked...