Collected research
Stripping Referrer for fun and profit
Kotowicz strips the Referer header from cross-origin GET and POST requests using client-side code only, with no server involved. Chrome loses it through a data: URI, IE through window.open, Firefox and WebKit need a data: URI plus a meta refresh, and POST adds a nested data: URI with an auto-submitting form. That defeats referrer-based CSRF defences.
Record
- Published by
- blog.kotowicz.net
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of blog.kotowicz.net, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .