Setting the ‘Referer’ Header Using JavaScript
ID: 7f0bf087-1d22-5fdc-9ef2-12ad9f244fac
STIX ID: report--7f0bf087-1d22-5fdc-9ef2-12ad9f244fac
Feed Name: TrustedSec blog
Threat Score
This blog post demonstrates a practical JavaScript technique that fakes the HTTP Referer header by modifying the browser history (pushState/replaceState) before issuing requests, enabling attackers exploiting XSS to make actions appear to come from legitimate pages; it includes example payloads, mitigation notes (limitations such as URL encoding and visible URL change), and links to code and prior related resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
