Sr. Web Developer
mediabistro.com
US-NY-New York

Justtechjobs.com Post A Job | Post A Resume

Comments for: chriskings20001128

Message # 1004090:
Date: 02/24/01 16:37
By: Hugh
Subject: (yet(yet)) another possible

There's quite an interesting possible way of hacking cookies back and forth - by using javascript source includes plus scripting -

eg..
user at domain1.com has cookie for that domain.

visits page on domain2.com which has -
<script language=javascript src=http://domain1.com/spit_js.php></script>
the request for spit_js.php will have the domain1.com cookie attached.
spit_js.php can then (by sending Content-type: application/x-javascript\n\n) spit the javascript code: document.cookie = ...
As the javascript 'appears' in a page on domain2.com it's allowed to set cookies for that domain...

just a 2p thought. As someone else points out, it'll probably be disabled in newer versions of browsers with paranoia > 1.0

H

Previous Message | Next Message


Comments:
Cross DomainLavanya05/23/08 03:23
RE: (yet(yet)) another possibleGuus derks12/13/07 04:48
RE: Cross Domainsamantha02/19/05 07:03
RE: EASIER Cross DomainMichael10/28/03 19:56
Setting cookies on a Linux WebserverSiva10/17/02 02:07
RE: expiring cookies.Keri Henare07/25/02 04:01
RE: (yet(yet)) another possibleDanny Tuppeny09/12/01 09:28
RE: Great, why use rewrite at all?Danny Tuppeny09/12/01 09:24
RE: Why not use redirection?Danny Tuppeny09/12/01 09:22
expiring cookies.nagaraj09/12/01 05:50
RE: Privacy Concerns of John Q. PublicJesse08/03/01 14:49
(yet(yet)) another possibleHugh02/24/01 16:37
RE: Not a sessionPhil Greenway02/15/01 16:33
RE: Another methodDavid Davis02/02/01 14:16
Yet another waysander12/16/00 15:15
RE: I think I would have...Chris Kings-Lynne12/04/00 21:08
RE: Another methodMatthew Kendall12/04/00 02:26
Another methodAndrew Dickinson12/03/00 15:09
Privacy Concerns of John Q. PublicJim Hawley12/02/00 11:07
Great, why use rewrite at all?Brian Tanner12/01/00 20:51
Why not use redirection?Johannes Erdfelt12/01/00 14:17
RE: CookiesHreinn Beck12/01/00 04:51
I think I would have...Paul K Egell-Johnsen11/30/00 13:13
RE: Cross DomainmarcoBR11/29/00 20:14
RE: Cross DomainRobert11/29/00 19:25
deleting cookiesDonncha O Caoimh11/29/00 08:03
Cross DomainMicheal O Shea11/29/00 07:23
 

If you are looking for help, please post on the appropriate forum here. Your questions will be answered much more quickly.

Add A Comment:

Name:

Email:

Subject:

Message:

To reduce spam posts, messages are now manually approved

You are not [logged in]. That means your account will not get credit for this post.