3 ms·
If you want to provide access to an API, put the API on a separate subdomain. That's why api.flickr.com has an open crossdomain.xml file and flickr.com doesn't.
by danielh 17y ago
If you want to provide access to an API, put the API on a separate subdomain. That's why api.flickr.com has an open crossdomain.xml file and flickr.com doesn't.
That's what I was referring to. OP listed domains which are probably used exclusively to provide an API, e.g. api.ebay.com, implying that the crossdomain files on these domains pose a security risk.
I was wondering if my comment is understandable, obviously it's not :) Thanks for the clarification!
- deleted 17y ago[deleted]
- wendroid 17y agoAnd you are right, a * is not a exploit but the starting point of looking for one. You still need to get content on the domain somewhere and ppl to read it, I was taking that as a given from the description of the problem which states that explicitly. tbh I just did a google for crossdomain ext:xml and pulled out the famous domains with * in the policy.