4 ms·
Yes and no. No, because it cannot be used as an exploit. Yes, because it allows you to read the address of the "top" object. Consider it similar to the CSS l
by Panos 16y ago
Yes and no.
No, because it cannot be used as an exploit.
Yes, because it allows you to read the address of the "top" object.
Consider it similar to the CSS link-color hack to read the past browsing history of a user.
- code_duck 16y agoBy 'exploit' I mean bending the rules, or skirting restrictions. Information disclosure, not code execution. They are taking advantage of flaws in browsers in order to gather information which is not supposed to be available. I assume this same method could be used by people with less savory goals, but this company isn't reporting the security flaws in browsers that let them do this as it would make things more difficult for their business. I probably wouldn't go around telling everyone if it was me.