wdrl.
  • Latest Edition
  • Archive
  • Evergreen
  • About
  • Contribute

The target="_blank" vulnerability by example

Hi, I’m Anselm Hannemann. Freelance webdesigner, frontend engineer, advisor. Curating WDRL, growing vegetables on a market garden farm.

Profile photo of the author, Anselm Hannemann

This link appeared in WDRL 151 on 26.08.2016.

The target="_blank" vulnerability by example

I recently shared an attack abusing target="_blank" on pages where users can add custom URLs. To make clear how bad the attack is, Ben Halpern now shows how he made it work on Instagram (they fixed it pretty fast). . So remember to use rel="noopener" for any URL that you didn’t hard-code into the source.

This link appeared in the 2016 Yearbook.

Profile photo of the author, Anselm Hannemann

Other projects

  • Freelance Portfolio
  • Food producer CSA
  • Colloq Event Platform
  • Workingdraft Podcast
  • Nightlybuild Conference

Sitemap

  • Privacy Policy
  • RSS
  • Donate
  • About
  • Testimonials

Legal

© 2023 and made by
Anselm Hannemann
Hofmark 14
82393 Iffeldorf
Germany
mail@wdrl.info

👋
Read the WDRL in your email inbox:

I respect your privacy and never share details with others than my service providers. By subscribing, you agree to the Privacy Policy. You can opt-out of the mailings any time again.

Give 5€ / month 10€ one-time PayPal