Collected research
Cross Site URL Hijacking by using Error Object in Mozilla Firefox
Firefox's script error handling reports the exact source URL that caused an error, and that reporting crosses origins. Deliberately triggering a fetch error against another site therefore discloses the destination URL reached after redirection, revealing whether the victim is logged in and exposing any confidential query parameters such as a session ID.
Record
- Researcher
- Soroush Dalili
- Published by
- soroush.me
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .