What are the security risks when using cross-domain XMLHttpRequest?

In many places, I saw people talking about the XML-HTTP prototype Cross-Domain, which is not possible due to some security concerns . However, I did not find a message stating what these security reasons really are?

People mentioned that JSONP is one of the good alternatives. Another alternative would be to use Originand headers Access-Control-Allow-Origin.

However, I just want to know what security issues can be caused due to the use of cross-domain XMLHttpRequest?

+5
source share
3 answers

, .

(example.org). script, AJAX facebook.com/messages/from/yourgirlfriend. facebook, Facebook, . Facebook , , . , , , , .

, , , , .

?

+9

" " , , . , , , .

- , google, , SO, . , XSS . XHR gmail.com . CSRF , .

, Google Browser. , , , .

Access-Control-Allow-Origin: *, , - . . CSRF, . Captsca , ( , HTTPS). CSRF.

+2

, , Javascript ( / ), ( ), , ( XMLHttpRequests , , ). .

JSONP - , , .

EDIT: : (, gmail yahoo). ( ) . XHR . XHR , /, , , - , , ( - , , ..). : - Javascript XHR . (, , ) , ( ). , , , , ( /..etc). , .

+1
source

All Articles