4 ms·
>In your example about bypassing the cross-origin policy, POST requests in general are allowed to be cross-origin by default, so unless you're explicitly blocki
by wormhole11 8y ago
>In your example about bypassing the cross-origin policy, POST requests in general are allowed to be cross-origin by default, so unless you're explicitly blocking that using something like an iFrame, a 3rd-party script can already just send requests directly.
Not sure what you're trying to say here, as far as I know CORS is applicable to all HTTP methods except OPTIONS when using Ajax. If you're saying that it's allowed using Forms, then that's allowed for all HTTP methods as we're navigating away from the page.
- danShumway 8y agoAgreed, I phrased that poorly. What I mean is that you can send a POST request to any server from a webpage unless the page you're on has taken specific steps to mitigate that attack. The remote server might have CORS headers set up so that the browser blocks the request. However, in this scenario (stealing payment information) we're talking about an attacker sending data to a remote domain that they control, so you really can't trust that they're going to block third-party AJAX requests to their own domain for their own attack. To block requests or form actions from your own page, you'd need to explicitly set a CSP header, which isn't something that's on by default. Note that a CSP header does not protect you if you're using HTTP, because I can just turn your CSP header off when I intercept the unencrypted page.