3 ms·
Cross Site Script Inclusion. The article touches on a lot of things (including CSRF), but the HN title refers specifically to JSON (As well as the link's '#' fr
by personalcompute 15y ago
Cross Site Script Inclusion. The article touches on a lot of things (including CSRF), but the HN title refers specifically to JSON (As well as the link's '#' fragment identifier), and therefore the last section, where it shows an attack site including unprotected JSON through the <script> tag, and unless I'm seriously mistaken, this is the definition of XSSI.
- pmh 15y agoYes, this is XSSI and the exploit comes in because a JSON array is essentially treated as "executable" code in some JS implementations. Here are a couple of resources that go a litle more into XSSI: Google tech talk: http://www.youtube.com/watch?v=jC6Q1uCnbMo&feature=player_detailpage#t=2306s http://www.youtube.com/watch?v=jC6Q1uCnbMo&feature=playe... Gruyere codelab: http://google-gruyere.appspot.com/part3#3__cross_site_script_inclusion http://google-gruyere.appspot.com/part3#3__cross_site_script...