This project is not maintained anymore. You can still view and search the archives.

wdrl.
  • Archive
  • Evergreen
  • About
  • Contribute

The target="_blank" vulnerability by example

Hi, I’m Anselm Hannemann, a freelance Frontend Developer and Engineering Manager. You can hire me. I wrote WDRL for 10 years and have a a Market Garden as a side-business.

Profile photo of the author, Anselm Hannemann

This link appeared in WDRL 151 on 26.08.2016.

The target="_blank" vulnerability by example

I recently shared an attack abusing target="_blank" on pages where users can add custom URLs. To make clear how bad the attack is, Ben Halpern now shows how he made it work on Instagram (they fixed it pretty fast). . So remember to use rel="noopener" for any URL that you didn’t hard-code into the source.

This link appeared in the 2016 Yearbook.

Profile photo of the author, Anselm Hannemann

Other projects

  • Hire me as Developer or Scrum Master
  • My food produce CSA

Sitemap

  • Privacy Policy
  • RSS
  • Donate
  • About
  • Testimonials

Legal

© 2026 and made by
Anselm Hannemann
Hofmark 14
82393 Iffeldorf
Germany
mail@wdrl.info