Peculiar type of cross-domain scripting
Posted: Fri Apr 01, 2016 10:42 pm
So I happened upon this demonstration of some sort of cross-domain scripting that I've never seen before:
https://mathiasbynens.github.io/rel-noopener (benign POC page)
Now, the malicious potential doesn't seem that high, for now, but maybe it's worth warning NoScript users when this trick is used in suspicious circumstances. Such as a page from another domain manipulating the original page.
What are you guys' thoughts on this?
Apologies if this is old news to you, by the way.
https://mathiasbynens.github.io/rel-noopener (benign POC page)
Now, the malicious potential doesn't seem that high, for now, but maybe it's worth warning NoScript users when this trick is used in suspicious circumstances. Such as a page from another domain manipulating the original page.
What are you guys' thoughts on this?
Apologies if this is old news to you, by the way.