People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!
blog.example.com and account.example.com, then the account page would have a JSONP endpoint. This works because of the cookies on the current page that get used. To prevent cross-data leakage, the endpoint verifies that the Referer header is whitelisted.Cache-Control, Expires and Last-Modified. Referer header, it will return the response to this request without doing the check! This becomes an authentication issue as a result. Cache-Control headers. I personally hadn't considered browsing caching as a security issue but it is in this case!