Skip to content

Commit

Permalink
Merge pull request #993 from souravvvv123/master
Browse files Browse the repository at this point in the history
Update other-web-tricks.md
  • Loading branch information
carlospolop authored Feb 3, 2025
2 parents f8c499d + 9f7827c commit 820cd6e
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions src/other-web-tricks.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,3 +36,6 @@ Developers might forget to disable various debugging options in the production e

{{#include ./banners/hacktricks-training.md}}

### Same-Site Scripting

It occurs when we encounter a domain or subdomain which resolves to localhost or 127.0.0.1 due to certain DNS misconfigurations.It allows an attacker to cheat the RFC2109 (HTTP State Management Mechanism) same origin restrictions, and therefore hijack state management data. It may also allow cross-site scripting. You can read more about it from [here](https://seclists.org/bugtraq/2008/Jan/270)

0 comments on commit 820cd6e

Please sign in to comment.