Insecure by default – hijacking websites that use target=“_blank”
devproving.com
devproving.com
Fortunately, tabs created by opening the link using the middle mouse button don't seem to have a useful window.opener. Guess I'll be more deliberate about that habit.
Edit: if I understand correctly this only allows the opened page to navigate the opening page; it does not allow it to do anything else to the opener. Is that correct?
link.html:
<a id="link" href="opener.html" target="_blank">Click</a>
opener.html: <script>window.opener.document.getElementById("link").href = "https://google.com";</script>
and sure enough the link was changed. If this works cross-domain, this is kind of a big deal, isn't it?It's a fairly big deal, but not much is being done about it on the browser side of things. It can only really be used for phishing style attacks.
I assumed we were still talking about window.opener.location (which can be modified across domains)
I too want to know
This property has limited functionality but one of the things that are allowed is redirecting the page to something else which is kind of unexpected.
The problem is not websites that use target="_blank", it's browsers that refuse to fix this behavior because of some ill-defined compatibility issue that appears to exist mostly in the heads of developers who don't want to work on a fix.