• MotoAsh@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    18 days ago

    Would data exfiltration work, though? I forget exactly what the header value is, and am far too lazy to look it up right now, but I’m pretty sure there’s a standard one that lets a website define where requests should be allowed to point at. Unless they’re scraping the data themselves, but then that hardly needs malicious JS.