top | item 37917271

(no title)

adraenwan | 2 years ago

maybe OP tried it's exploit in internet explorer 5.0, but I doubt it'll work in any recent (read: less than 5 years old) browser.

discuss

order

masklinn|2 years ago

Modern browsers will straight up tell the server the resource is being loaded from an iframe via Sec-Fetch-Dest.

henriquez|2 years ago

Oh it works. Just Google sqword if you don’t believe.