Target=“_blank” – the most underestimated vulnerability ever
jitbit.com
jitbit.com
Anyone know why this isn't considered a bug and fixed? What is a legit use of a window changing it opener location crossdomain? I get it in the same web site / app.
Dear browsers, please just remove this feature.
Allow resizing of windows
Allow moving of windows
Allow raising of windows
Allow lowering of windows
Allow changing of status field
Allow scripts to detect context menu events
Allow script to hide address bar
Enable frames
Enable inline frames
Send referrer information
+ability to disable/set detailed quota/readonly for HTML5 local storage/cookies
Modern browser should probably throw in ability to disable/block AudioContext/ navigator.mediaDevices/ navigator.getUserMedia/ HTMLCanvasElement.prototype.toDataURL/ HTMLCanvasElement.prototype.toBlob/ CanvasRenderingContext2D.prototype.getImageData/ WebRTC/ navigator.sendBeacon/ window.opener
I'm surprised it can't be addressed. Is being able to modify the referrer location that difficult to lock in various ways?
On macOS 10.15.2 (19C57) using Safari 13.0.4 (15608.4.9.1.3), the proofs of concept mentioned in the article yield
> The previous tab is safe and intact. window.opener was null; mischief not managed!
Perhaps your dismissal of Safari is presumptive and mistaken.
Security issues need secure solutions, right?
I don't actually see the utility in allowing open access from child page to parent page, especially when cross-server is a factor. There are similar other issues that have been closed. Why not this one?