4 ms·
This is way over my head but seems very problematic.
by lightyrs 14y ago
This is way over my head but seems very problematic.
- homakov 14y agoyes, explanation is a bit short. i can explain if any part is unclear
- eranation 14y agoyes, please, if you could explain for non security experts what we can do to protect our pages from this vulnerability, and also please clarify if it's relevant to web pages that don't use frames / iframes (I guess some of us just shrug and say, "hm.. clever post, I wish I had the time to dive into this, but I don't plan to try to use this to attack other sites, and it's probably not relevant for me since I don't have any frames" so a simplified clarification will be highly appreciated)
- homakov 14y ago1) SAMEORIGIN/DENY is good protection, as said above 2) If you don't interact with frames(window.length==1) and don't have Like buttons - you are not vulnerable
- KwanEsq 14y agoUnless I'm misunderstanding scenario is this: 1) Fancy app website uses iframes to send messages to itself/its server 2) attack website embeds app in an iframe 3) attack website changes the URLs of the apps iframes to point to attacker-controlled pages 4) app sends sensitive info to its iframes, which of course ends up going to the attacker
- homakov 14y agoyes, thats right