answersLogoWhite

0


Best Answer

In short: Yes, a cross-site scripting attack (XSS) can be used to access cookies. This is a big part of the reason why you shouldn't rely solely on cookies to identify a user.

In 2006, LiveJournal was a victim of just this style of attack. You can read about it in detail in the related links. Since then, browsers have implemented security measures making this kind of attack far more difficult to implement (but not impossible.)

User Avatar

Wiki User

11y ago
This answer is:
User Avatar

Add your answer:

Earn +20 pts
Q: Can a cross-site scripting attack coded in javascript access your cookies?
Write your answer...
Submit
Still have questions?
magnify glass
imp
Continue Learning about Engineering

How does files in javascript act as a backend?

Javascript is a client-side script, meaning it runs only in the browser. It has no access to the server. For access to the server, thus creating a back-end, you need to use a server-side scripting language such as ASP or PHP. If you want to make a more fluid interface, JavaScript and AJAX can be combined with one of the two aforementioned server-side scripts, effectively creating a back-end and a front-end.


What is negative infinity javascript?

To access infinity in JavaScript use the JavaScript keyword "Infinity." To access negative infinity, place the minus sign in from of the keyworld "-Infinity." See the attached JSFiddle for associated code.


Java sript vs VB script?

Hi all, javascript is case sensitive vbscript is not. javascript will explore in all the browser, vb accept only internet explore javascript only for client side, vbscript both client side and serverside js is client side validation,vbscript for server side validation if you don't get. u can reach me iamselvam85@gmail.com


How do you restart your computer with JavaScript?

There is no known way to restart a computer system in Javascript. Javascript is a web programming language that allows web page functionality such as user input, animation, creatings graphs or charts, and making changes to a page based dynamic data.


What are client side and server side scripting?

Client side scripting is a script, (ex. Javascript, VB script), that is executed by the browser (i.e. Firefox, Internet Explorer, Safari, Opera, etc.) that resides at the user computer. Server side scripting, (ex. ASP.Net, ASP, JSP, PHP, Ruby, or others), is executed by the server (Web Server), and the page that is sent to the browser is produced by the serve-side scripting. So when a server sends out a page, it executes server-side scripts, but does not execute client-side scripts. Once the browser receives the page, it executes the client-side scripts. Server side scripting can connect to databases that reside on the web server or another server reachable from web server. Client side scripting cannot do that. Server side scripting can access the file system that reside at the web server, client side cannot. Server side scripting can access settings belong to Web server while client side cannot. Client side scripting can access files and settings that are local at the user computer. Client side scripting consumes cycles from user's computer not web server one, while server side scripting consumes cycles form web server one.

Related questions

Is it possible to access browser cookies from javascript?

Yes, it is possible to access browser cookies from JavaScript. It can be done using cookies keyword inside it.


How do i get battery level in javascript?

That's not possible. Javascript is a browser-based scripting language. Thus, it only has access to DOM objects. If you are making a desktop application and want access to that sort of thing, try Visual Basic, C, C++, C#, etc.


What are the scope and limitation of the javascript?

The scope of JavaScript includes client-side web development, server-side scripting, and creating desktop and mobile applications. JavaScript is limited by security concerns, browser compatibility issues, and its inability to directly access system resources. Additionally, JavaScript may not be suitable for heavy computational tasks.


Why does Yahoo say you need cookies to access your Yahoo email?

Cookies are basically scripting, and it needs to load cookies on your browser to use their custom flash player, (I believe) and it puts data on the website so it can optimize your experience.


How does files in javascript act as a backend?

Javascript is a client-side script, meaning it runs only in the browser. It has no access to the server. For access to the server, thus creating a back-end, you need to use a server-side scripting language such as ASP or PHP. If you want to make a more fluid interface, JavaScript and AJAX can be combined with one of the two aforementioned server-side scripts, effectively creating a back-end and a front-end.


What is negative infinity javascript?

To access infinity in JavaScript use the JavaScript keyword "Infinity." To access negative infinity, place the minus sign in from of the keyworld "-Infinity." See the attached JSFiddle for associated code.


How do you write javascript?

JavaScript is a non-compiled scripting language and can be written in any plain-text editor, just like HTML and CSS. The added complexity of JavaScript, however, means that most programmers are using at least a tool to provided syntax highlighting, like NotePad++. If you have access to a more full-featured IDE like Dreamweaver or Eclipse, you may want to use it, as the tools provided go a long way to taking some of the headache out of programming.


What is the scripting engine access in InteractiveBuddy?

you simply type ine what you want to do


What are the disadvantages of disabling JavaScript in your browser?

The disadvantage of disabling JavaScript is that when you access a website that uses JavaScript (which a lot of websites do) they may not look or work properly or may ask you to enable it.


How do you transfer values from javascript to JSP?

You can set the value in the hidden form fields using javascript and access the form fields in JSP


How do you create a webpage that needs a survey to get in?

To create a webpage that requires a survey to grant access, you can use a combination of HTML for the webpage structure and JavaScript for form validation and survey submission. Set up the survey questions within a form element on the webpage and use JavaScript to check the survey responses before allowing access to the rest of the page’s content. Consider using server-side scripting (e.g., PHP, Node.js) to handle the form submission and authenticate users based on their survey responses.


What are the scripting engine access codes for inter active buddy?

u ust type in buddylovesme