Web Hack List

Other nomination

Stripping Referrer for fun and profit

Kotowicz strips the Referer header from cross-origin GET and POST requests using client-side code only, with no server involved. Chrome loses it through a data: URI, IE through window.open, Firefox and WebKit need a data: URI plus a meta refresh, and POST adds a nested data: URI with an auto-submitting form. That defeats referrer-based CSRF defences.

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.