Abusing JSONP with Rosetta Flash
miki.it
miki.it
> if possible use a dedicated sandbox domain.
It's 2014. You don't have to use JSONP and open up your domain to XSS; just use standard and safe XHR with CORS[1]. Every major browser has supported it for years, and for very old browsers that don't support CORS (IE 8), I wrote pmxdr[2] five years ago.
[1]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_con...
That's one substantial drawback.
[1](http://krebsonsecurity.com/2014/05/the-mad-mad-dash-to-updat...)
I gave a talk about the potential for this to happen about a year ago: http://quaxio.com/jsonp_handcrafted_flash_files/
http://www.slideshare.net/guest2821a2/web-browsers-and-other...
http://www.slideshare.net/guest2821a2/web-browsers-and-other...
Actually going out and doing it is something else.
JSONP itself, though yucky, should still be safe from XSS given a /-star-star-/ prefix and a validated callback parameter.
I think that is the "waiting to happen" part of my initial comment.