Web Hack List

Collected research

Safari: a tale of betrayal and revenge

Explains a Safari same-origin bypass caused by disagreement between WebKit’s KURL parser and CFNetwork. Hostless-looking HTTP URLs receive authenticated content from distinct servers while origin checks treat both as having an empty host. A data-URL transition supplies the parsing context needed to trigger the discrepancy from a webpage; Safari 4.1 and 5.0 fixed the flaw.

Record

Researcher
Michał Zalewski
Published by
lcamtuf.blogspot.com
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Michał Zalewski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .