Collected research
Same Origin Method Execution (SOME)
Same Origin Method Execution abuses callback endpoints such as JSONP handlers and Flash applets, whose callback parameter is echoed into executable script. By opening windows and redirecting their documents, an attacker makes the callback value a DOM path aimed at a victim page and fires arbitrary methods on any page of that domain using only alphanumerics and a dot.
Record
- Researcher
- Ben Hayak
- Published by
- benhayak.com
- Topic
- Browser
In the archive
Related sources
- eu 14 Hayak Same Origin Method Execution Exploiting A Callback For Same Origin Policy Bypass wp Whitepaper
- Same Origin Method Execution Whitepaper
- Same Origin Method Execution Slides
- Same Origin Method Execution (SOME) - Exploiting a Callback for Same Origin Policy Bypass
Tags
This page is the archive's own catalogue record. The research is the work of Ben Hayak, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .