Web Hack List

Collected research

Stripping Referrer for fun and profit

Kotowicz strips the Referer header from cross-origin GET and POST requests using client-side code only, with no server involved. Chrome loses it through a data: URI, IE through window.open, Firefox and WebKit need a data: URI plus a meta refresh, and POST adds a nested data: URI with an auto-submitting form. That defeats referrer-based CSRF defences.

Record

Published by
blog.kotowicz.net
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of blog.kotowicz.net, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .