How I got XSS’d by my ad network
troyhunt.com
How I got XSS’d by my ad network
1–10 of 62 posts
Re: How I got XSS’d by my ad network
#2Re: How I got XSS’d by my ad network
#3Re: How I got XSS’d by my ad network
#4I've seen a fair few Internet banking web sites pulling scripts from over a dozen third parties, mostly for tracking and advertising, but even for trivial things like social media. On their customer login pages. It's beyond me how they can consider this to be an acceptable risk.
Re: How I got XSS’d by my ad network
#5With http2, relevant javascript files will be increasingly hosted on the same domain anyway and that option would become increasingly relevant.
Re: How I got XSS’d by my ad network
#6This is why browsers should have an option "Block third party javascript" similar to "Block third party cookies". With http2, relevant javascript files will be increasingly hosted on the same domain anyway and that option would become increasingly relevant.
With http2, relevant javascript files will be
increasingly hosted on the same domain
Why is that?Re: How I got XSS’d by my ad network
#7"When you allow third parties to run script on your site, you’re entirely beholden to them; they can run anything they like in the context of your site" I've seen a fair few Internet banking web sites pulling scripts from over a dozen third parties, mostly for tracking and advertising, but even for trivial things like social media. On their customer login pages. It's beyond me how they can consider this to be an acce…
Re: How I got XSS’d by my ad network
#8This is why browsers should have an option "Block third party javascript" similar to "Block third party cookies". With http2, relevant javascript files will be increasingly hosted on the same domain anyway and that option would become increasingly relevant.
With http2, relevant javascript files will be increasingly hosted on the same domain Why is that?
[0] https://mattwilcox.net/web-development/http2-for-front-end-w...
Re: How I got XSS’d by my ad network
#9Re: How I got XSS’d by my ad network
#10This is why browsers should have an option "Block third party javascript" similar to "Block third party cookies". With http2, relevant javascript files will be increasingly hosted on the same domain anyway and that option would become increasingly relevant.