Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because you cannot issue cross-domain AJAX calls, the attacker does not have access to the response body as a string that can be manipulated.

https://secure.wikimedia.org/wikipedia/en/wiki/Same_origin_p...



Oh duh, I'm dumb.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: