4 ms·
Same Origin Policy would prevent AJAX requests, CSRF attacks thus usually use hidden forms -- window.open achieves the same, but with the opportunity to send mu
by dnet 11y ago
Same Origin Policy would prevent AJAX requests, CSRF attacks thus usually use hidden forms -- window.open achieves the same, but with the opportunity to send multiple requests.
- aakilfernandes 11y agoAh good point. Couldnt they of just included fake images or iframes instead?
- juliangregorian 11y agoYou could still use hidden forms to send multiple requests, just set the form target to "_blank". You can't, however, send POST requests any other way.
- kpcyrd 11y agoThis isn't the case anymore. Since CORS was introduced, you can send xhr GET Requests to arbitrary domains. The browser then checks if the appropriate CORS headers are set. If they are, you can access the response. If they aren't, you can't. As a sane developer you are supposed not to trigger ANY actions on a GET anyway and there are a lot more ways to trigger them, so this is not an issue in the browser. For POST and friends it's a bit more complicated, the browser sends an OPTIONS request first and checks if the CORS headers are set and only if they are, the actual POST is submitted. Fun Fact: It looks like it's possible to exploit this issue silently even with javascript disabled and NoScript installed, it's quite lame to do it the way they did.