Same Origin Policy of browsers Often times we have heard that Javascript cannot send requests to another domain. That is because of the same origin policy implemented in the browsers. The same origin policy of the browsers prevents document or script loading from a different domain to manipulate the document loaded from current domain, without which javascript from a malicious domain could do any number of adverse things such as log keystrokes, steal cookies, modify your data, or even insert unwanted transactions while you do your online banking, etc. Hence,
Read full article from Anurag Agarwals' Threat Modeling Blog: Breaking the Same Origin barrier of Javascript
No comments:
Post a Comment