Upgrade to Pro — share decks privately, control downloads, hide ads and more …

HappyDev 2015

ar7z1
December 06, 2015

HappyDev 2015

Доклад о "клиентских" атаках на веб-приложения и о том, что может произойти, если не думать о защите.

ar7z1

December 06, 2015
Tweet

More Decks by ar7z1

Other Decks in Programming

Transcript

  1. var r = new XMLHttpRequest(); r.open('POST', ‘http:// site2.com’, true); r.setRequestHeader(‘Content-

    Type’,'application/json'); r.setRequestHeader('X-HEADER', 'lalala'); r.send(data);
  2. Cross-origin writes var c = new XMLHttpRequest(); c.withCredentials = true;

    c.open("POST", ...); c.setRequestHeader("Content- Type", “...”); c.send(...);