Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
The Extended HTML Form attack revisited (enablesecurity.com)
12 points by sandrogauci on June 18, 2008 | hide | past | favorite | 1 comment


I'm wondering if this could be prevented by considering different ports as different domains in the context of cookies and scripts, rather than blocking port numbers. I know that would raise an issue when mixing HTTP and HTTPS, but I was under the impression that such mixing already is locked down.

Thoughts?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: