Why do browsers prevent cross-site AJAX? -


what of examples of attacks made if possible?

i run website gives away best free pornography in town. people flock it.

as browsing , viewing spectacle of colours , moving imagery, ajax request works it's way through list of domains seeing if logged in of them.

any logged into, send ajax request page on site saves of data has found. way steal private information.

or, can post data forms on pages, along lines of "send me £1000 bank plz k thx".

http://en.wikipedia.org/wiki/same_origin_policy

why cross-domain ajax security concern?


Comments

Popular posts from this blog

python - Does anyone know how to configure the hunpos wrapper class on nltk? -

mysql - How to insert just year and month into date field? -