Why does Google append while(1); in front of their JSON responses?
stackoverflow.com
stackoverflow.com
So a malicious website can't steal that content by putting the URL in a script. It will never get to see what's in the script and only a same-domain script could parse the whole contents, by making a XHR call, and strip out the "while 1;" part. In contrast, a regular JSONP string is specifically designed for the third party to read it (by including code to call a callback function).
A lot of people still don't realise you shouldn't be serving private data as JSONP. Thankfully, CORS lets modern browsers go cross-browser safely, even with private data if things are configured right.
Would you clarify or add some pointers to where we can learn about CORS benefits for private data? CSRF is a huge but often underestimated issue.
That said, a benefit of CORS is the ability to do non-GET methods. So it's safer in the sense of HTTP idempotence, ie you can change server state safely, using POSTs, DELETEs, and so on. You'd still need to pass a token, however.
(Of course I meant cross-domain, not cross-browser :).
> safely, even with private data if things are configured right.
CORS does nothing to prevent CSRF attacks, see[1]. We still need to protect against CSRF.
XSRF vulnerabilities allow an attacker to issue web requests on a user's behalf; oftentimes though people only call it a vulnerability when you can issue a request that changes some state. And XSRF is usually prevented by including a hard to guess token with the request that is tied to the user and allows you to determine whether the request was generated by an authorized party. Please don't try to prevent XSRF by using while(1) :)
Perhaps the trio of "affix", "prefix" and "suffix" might be more useful, since there is no "postpend" or "suppend" to accompany "append" and "prepend".
Regardless, the Google ngram chart of these various words is pretty interesting: http://books.google.com/ngrams/graph?content=prepend%2Cappen...
3
[1, 2, 3, 0]
If you execute that in your JS console, it'll return undefined, which threw me for a loop a couple days ago when I saw it. I ended up having it ask on StackOverflow too and it's because JavaScript will interpret it as a property look up on that number object (it will evaluate to 3[0], which evaluates to undefined).
Using POST is not sufficient; you also need to include an XSRF token that only the requesting page knows. It's very possible to send a POST to a third-party site with about one line of Javascript. (In the relatively early days of Reddit, I wrote a page that upvoted itself by having a JS handler in an invisible iframe resubmit the same link over again, using the visitor's login credentials. At the time, submitting the same link twice on Reddit counted as an upvote, and so merely visiting the page would upvote the link.)
Security issues are obviously more complex than one-line explanations. Thank you for your more elaborate reply!
Good 'ol stackoverflow
First off, you can still read the question and vote on answers. Since there are already several answers, adding another one would not be very useful anyhow.
Moreover, it's closed as a duplicate. There's an essentially identical question--with essentially the same answer--that's quite a bit older. It makes sense to point people to it so that there's one centralized resource on the topic.
However, I certainly see how it would be useful to have the link in the closed message as well.
http://stackoverflow.com/questions/871505/
Which is, itself a duplicate of this question, which has an even better answer:
Every organization becomes controlled by those who serve the organization itself, as opposed to those who perform the actual goal or service of the organization. Schools are controlled by administrators, not the teachers. Wikipedia and other community-sourced internet sites are run by those who desired to acquire power over Wikipedia, not by those who desire to contribute content.
It has? It's news to me; I'm constantly finding relevant, useful information whenever I search for almost anything in the area of software development.
http://lists.webappsec.org/pipermail/websecurity_lists.webap...
Rails and Django patches/recommendations on the issue: http://weblog.rubyonrails.org/2011/2/8/csrf-protection-bypas... https://docs.djangoproject.com/en/1.2/releases/1.2.5/#csrf-e...
http://jeremiahgrossman.blogspot.com/2006/01/advanced-web-at...
Now I find that workaround sweet: but it's still a total kludge and that such kludges are used just shows how poorly security has been conceived from the ground up in browsers / JavaScript.
Content Security Policy makes all this much more robust in modern browsers.