Why do browsers prevent cross-site AJAX? -
what of examples of attacks made if possible?
i run website gives away best free pornography in town. people flock it.
as browsing , viewing spectacle of colours , moving imagery, ajax request works it's way through list of domains seeing if logged in of them.
any logged into, send ajax request page on site saves of data has found. way steal private information.
or, can post data forms on pages, along lines of "send me £1000 bank plz k thx".
Comments
Post a Comment