Find Jobs
Hire Freelancers

A script to disable XSS (Same Origin Policy) restrictions

$250-750 CAD

Closed
Posted about 12 years ago

$250-750 CAD

Paid on delivery
All modern browsers are built with a restriction: the Same Origin Policy. This has been set up in order to avoid XSS (Cross-Site Scripting) manipulations. Imagine you have a simple .html file on domain [login to view URL] (YOURS), and this .html page is containing an iframe with src set to another domain, like [login to view URL] (NOT YOURS). From [login to view URL], you will usually be unable to access the DOM of y.com. Example, if instead of [login to view URL] this is [login to view URL], [login to view URL] won't be able to access any ID contained in [login to view URL] DOM. What I wonder now is, if there is ANY imaginable way to do this? I haven't been successful yet in my various trials, and one of my website needs to get the CURRENT src of the iframe. This is very easy to retrieve the src of the iframe since I defined it myself when scripting the iframe, however this is a whole other thing to get the CURRENT url of the iframe (because the user can navigate from link to link in that iframe, and I need to know if he is still on [login to view URL], or has moved out of that domain, so I need to get the CURRENT url of the iframe from a button located on x.com. Tell me if this is not clear. You can use Flash, Ajax, PhP, Java, .hta, vb, game engines, anything... just keep in mind that I have absolutely no control over the iframe content, except I can define the iframe source url. Please present me a working proof of concept or demo, else I will not hire you. This is almost an impossible challenge, but the answer to the problem is probably very short. I have a short budget for such a task (250-750$CAD), but I may find more money if this is working. Just provide me with a solid proof.
Project ID: 1408979

About the project

5 proposals
Remote project
Active 12 yrs ago

Looking to make some money?

Benefits of bidding on Freelancer

Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
5 freelancers are bidding on average $440 CAD for this job
User Avatar
We are team of advanced javascript programmer. Having experience of implementing cross domain origin support in website. We will also like to make a demo of your project if you wish.
$300 CAD in 30 days
5.0 (2 reviews)
3.0
3.0
User Avatar
Please see my PM, information attached
$250 CAD in 1 day
5.0 (1 review)
2.5
2.5
User Avatar
hello! i understand your requirements, please check your pmb.
$300 CAD in 10 days
0.0 (0 reviews)
0.0
0.0
User Avatar
HELLO SIR PLEASE CHECK PMB
$600 CAD in 6 days
0.0 (0 reviews)
0.0
0.0
User Avatar
Check PMB please.
$750 CAD in 1 day
0.0 (0 reviews)
0.0
0.0

About the client

Flag of CANADA
Acton Vale, Canada
0.0
0
Member since Dec 19, 2011

Client Verification

Thanks! We’ve emailed you a link to claim your free credit.
Something went wrong while sending your email. Please try again.
Registered Users Total Jobs Posted
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Loading preview
Permission granted for Geolocation.
Your login session has expired and you have been logged out. Please log in again.