Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

if evil.com is listed in the CORS http header from the legitimate domain.

That's not how CORS works; the header is read from the domain being called from JavaScript, not from the domain where the JavaScript came from. So in this case, the injected JS will call evil.com, and so the CORS headers will be read from evil.com.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: