Watch episode #550 of Enterprise Security Weekly in which Sven Morgenroth, our Security Researcher, talks about Same Origin Policy, its origin, how it works as a security measure, various incorrect implementation issues and dangers. The show includes slides and a demo of four exploits that abuse mistakes developers make when circumventing SOP.
Sven Morgenroth of Netsparker gave a technical presentation entitled ‘How to Circumvent the SOP and How to Get Hacked in the Process' during episode #550 of Paul’s Security Weekly. The presentation was about the Same-origin Policy (SOP), one of the most important security policies in web browsers, and during the presentation Sven explained:
During the presentation Sven also ran a demo showing several exploits by which developers can circumvent the SOP:
For each, Sven talked about how it works and what the dangers are. There are powerful tools to disable the SOP but they have to be used with care, as it is easy to get them wrong. The episode ended with a brief Q&A session, as Joff Thyer and Keith Hoodlet joined the show.
Here are the slides Sven used during the presentation and demo of Same-origin Policy.