Return Styles: Pseud0ch, Terminal, Valhalla, NES, Geocities, Blue Moon.

Pages: 1-

cross site scripting

Name: Anonymous 2007-03-21 6:41 ID:S44pPr3g

I wish to request a webpage on a different website and read some data from it, but doing this on the browser client rather than the web server.

I've tried IFRAME and XMLHttpRequest in various different ways but keep getting access denied errors due to cross-site scripting restrictions.

Any neat tricks around this?

Name: Anonymous 2007-03-21 7:24 ID:xDddWh5T

Obviously not.

Name: Anonymous 2007-03-21 7:44 ID:Heaven

obviously you lack knowledge of the intertubes.

Name: Anonymous 2007-03-21 8:55 ID:T2gYxmuA

AJAX Enterprise Scalable Solution for the win.

Name: Anonymous 2007-03-21 8:58 ID:HWEHjjhI

Referer tricks?

Name: Anonymous 2007-03-21 11:27 ID:wHdTT6iN

you gonna need a proxy due to cross-domain browser security lockdownz.

Name: Anonymous 2007-03-21 12:00 ID:Heaven

Any neat tricks around this?
yes.
and no, i won't tell you what they are. you'll have to find them yourself. of course by the time that happens someone who cares enough to endure the horror that is bugzilla will probably report the ones i know about and they'll probably be fixed.

Name: Anonymous 2007-03-21 13:36 ID:S44pPr3g

>>7

You're a poor liar

Name: Anonymous 2007-03-21 16:01 ID:xDddWh5T

>>8

Signed

Name: Anonymous 2007-03-25 5:00 ID:/Rihol8+

>>5
>>6
>>7
wrong.
use ajax to communicate w/ a php file on your server, and use that php file to get stuff from their server (using fopen on the webpages or cURL).

Name: Anonymous 2007-03-25 11:26 ID:Heaven

>>10
But that's not clientside, dipshit

Name: Anonymous 2007-03-25 14:40 ID:HciPZLN0

>>1
Of course it's not clientside you fucktard.
You CAN'T XSS fully clientside. This is just a work-around.

Name: Anonymous 2007-03-25 15:53 ID:Heaven

>>12
XSS is the problem, not what he wants to achieve. I quote:

I wish to request a webpage on a different website and read some data from it, but doing this on the browser client rather than the web server.

Name: Anonymous 2007-03-27 0:39 ID:w9FJz72R

You can't do XMLHttpRequest off the current domain. Soz.

Name: Anonymous 2007-03-27 18:12 ID:+E2pENpv

orz

Name: Anonymous 2007-03-27 18:16 ID:nXkHEQxy

Same-Domain Policy, bitch. Standard JavaScript implementation.

Name: Anonymous 2007-03-28 9:56 ID:Zi8dz8Re

You could use a Java applet. Normally if you use sockets you can only connect to websites on the same domain, but if you sign the applet you can also connect to different websites.

Name: Anonymous 2007-03-28 10:42 ID:Heaven

Name: Anonymous 2007-03-28 13:48 ID:8H05e93y

i know about and xmlhttprequest in various different websites on the web server and no i won't tell you lack knowledge of course by the browser security lockdownz yes and xmlhttprequest off the web server (using fopen on your server and xmlhttprequest off the same domain soz orz same-domain policy bitch standard javascript implementation you fucktard you can't do xmlhttprequest in various different website and xmlhttprequest in various different website and they'll probably be fixed you're a pdf  i quote: you fucktard you can only connect to cross-domain browser client rather than the ones i know about and use

Name: Anonymous 2007-03-28 15:03 ID:Heaven

What?

Name: Anonymous 2007-03-28 23:34 ID:Heaven

>>19-20
same person

Name: Anonymous 2007-03-29 9:06 ID:DrGX/Z2L

You are kidding arent you ? That sounds preposterous to me. I think you need to re-examine your assumptions.

Name: Anonymous 2009-03-06 8:04


Request at ChillingEffects org.

Name: Anonymous 2011-02-04 12:14

Name: Sgt.Kabu䥟쩛kimanꊗ⹼ 2012-05-28 23:37

Bringing /prog/ back to its people

Don't change these.
Name: Email:
Entire Thread Thread List