Judgment on bypassing refer

Source: Internet
Author: User

Think about a bunch of things. Let's make it easy!

I have two questions:

First, in the IE kernel, the drag-and-drop function includes refer.

For example, if you enter web.im.baidu.com directly, you cannot access it. You can access it in this way, and it should be the fastest.

Second, some cumbersome methods can also break through refer restrictions, such as pseudo protocols:

Javascript: document. write ("<a href = http://web.im.baidu.com> open </a> ")

I remember that the previous monyers game also had a judgment on refer. At that time, the xss principle was used to break through. In fact, there were quite a lot of other methods.

Recently readingAnethaThat's why the UI is really not written-so we should not be confused by the surface. In fact, his best things are in base. js, and his thoughts are very evil. As for how evil is, you can only know it after reading the code! You can also look at the following Architecture:

Evil! He's all under suspicion!

This is not completely completed yet. If it is all done, it should be no less important than jquery. We were cheated by the strong winds -- his anetha was not referring to this xss attack platform, but the stuff behind it that played a supporting role. Oh, with that thing, each of us can construct our own attack platform. According to the jquery line, this stuff may have countless plug-ins in the future. We chose plug-ins to construct a unique attack method!

Btw: I like this functional programming style very much. It's very clear to read, just like reading a novel. Hey hey!

Monyer

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.