Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is Stephan Di Paola's "Prototype Hijacking" attack, and it's more than 2 years old. We wrote it up here:

http://www.matasano.com/log/672/di-paolas-prototype-injectio...



Yeah, XSSI has been well known for a while.

This article's argument against using custom headers is a bit bunk. If you're not properly disabling proxy caching for sensitive data, you're asking for trouble anyways. Disabling caching properly is a bit tricky, but there are some useful details here: http://code.google.com/p/browsersec/wiki/Part2#Document_cach...


Perhaps there are some interesting corner-cases where the browser will locally cache the JSON. Time to go play with it...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: