The Same Origin Policy / Chapter 05 of 14

Same Origin Policy in Tabs

Same Origin Policy in Tabs in Pankaj Mouriya's Same Origin Policy guide.

All chapters ↘
  1. 01 / Introduction
  2. 02 / What should be Allowed?
  3. 03 / Same Origin Policy
  4. 04 / Access Different Orgins
  5. 05 / Same Origin Policy in Tabs
  6. 06 / Same Origin Policy to Anchors
  7. 07 / Same Origin Policy to Forms
  8. 08 / Same Origin Policy to Images and CSS
  9. 09 / Same Origin Policy to JavaScript
  10. 10 / Same Origin Policy to Web Storage
  11. 11 / Same Origin Policy to Cookies
  12. 12 / Getting Around Same Origin Policy
  13. 13 / postMessage API Implementation and limitations
  14. 14 / References

Remember each tab or window is isolated from each other. And as I mentioned earlier, each site has its own JavaScript context or say JavaScript execution environment

Whenever we create a reference to different window/site by creating a reference variable, the referenced website or windows has a reference back via window.opener.

Same Origin Policy in Tabs, figure 1

Lets see a live demo for this

Start by creating a reference to sitea.com from sitea.com

Steps -

  1. Visit sitea.com and open browser console.
  2. Type
Code
var bob = window.open('http://sitea.com')
Same Origin Policy in Tabs, figure 2
  1. Switch to sitea.com opened into new window and open Browser Console.
  2. Type
Code
window.opener.document.body
Same Origin Policy in Tabs, figure 3
  1. We are able to read data of origin sitea.com window.
  2. If you think from attacker perpective, what if referenced window can change the origin window location.
  3. Type
Code
window.opener.location.replace("https://example.com")
Same Origin Policy in Tabs, figure 4
  1. A malicious user can change location of origin window to any attacker controlled website
Same Origin Policy in Tabs, figure 5

This kind of attack is called Tab-nabbing attack

Note for Pankaj Read more about tab nabbing or any related attack. Also watch Kirk video where he explain attacks like this