TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The problems and some security implications of websockets

42 点作者 subudeepak大约 11 年前

2 条评论

leeoniya大约 11 年前
&quot;WebSockets is a nightmare because it does not come under the Same-origin policy.&quot;<p>yes, i discovered this myself about a week ago.<p>i was surprised that i was able to connect to a localhost websocket when using an internal app on another domain. i expected this to fail and require CORS like XMLHttpRequest. after rejoicing briefly that i didnt need to whitelist it and was saving 2min, i was pretty terrified.
评论 #7637185 未加载
评论 #7637096 未加载
ENGNR大约 11 年前
Can&#x27;t a malicious script scan the DOM and send sensitive info via an image GET request anyway?
评论 #7637291 未加载