Link with target=“_blank” and rel=“noopener noreferrer” still vulnerable?

前端 未结 4 1797
伪装坚强ぢ
伪装坚强ぢ 2020-11-28 23:41

I see people recommending that whenever one uses target=\"_blank\" in a link to open it in a different window, they should put rel=\"noopener noreferrer\"

4条回答
  •  一个人的身影
    2020-11-29 00:04

    You may be misunderstanding the vulnerability. You can read more about it here: https://www.jitbit.com/alexblog/256-targetblank---the-most-underestimated-vulnerability-ever/

    Essentially, adding rel="noopener noreferrer" to links protects your site's users against having the site you've linked to potentially hijacking the browser (via rogue JS).

    You're asking about removing that attribute via Developer Tools - that would only potentially expose you (the person tampering with the attribute) to the vulnerability.

提交回复
热议问题