The Same Origin Policy - Hacker History

  Рет қаралды 105,171

LiveOverflow

LiveOverflow

Күн бұрын

In 1995 Netscape invented JavaScript (LiveScript) and it marked the start of client-side web security issues. In this video we explore this history and learn about the same origin policy (SOP).
Cookies Explained: web.archive.org/web/199706052...
Netscape 2.0b1 LiveScript: web.archive.org/web/200212121...
Netscape 2.0b2 JavaScript: web.archive.org/web/200412111...
JavaScript Documentation: web.archive.org/web/199706132...
Netscape 2.02 Security Fixes: web.archive.org/web/200307111...
Netscape 3: web.archive.org/web/200208081...
Bugtraq Java Applet RCE: seclists.org/bugtraq/1996/Jun/27
Donate to Web Archive: archive.org/donate/
Chapters:
00:00 - Intro and Motivation
00:43 - How the Internet Works
01:43 - Online Services in 1994/95
03:08 - JavaScript Released in 1995
04:40 - HTML frames and framesets
05:16 - Cross-Domain Attack Example
06:54 - Fixing the Attack
08:00 - The First Web Exploit?
08:37 - The Same Origin Policy (SOP)
09:35 - Historical Context: Crashes, Java Applets, ...
11:06 - Outro and Shoutout
=[ ❤️ Support ]=
→ per Video: / liveoverflow
→ per Month: / @liveoverflow
=[ 🐕 Social ]=
→ Twitter: / liveoverflow
→ Instagram: / liveoverflow
→ Blog: liveoverflow.com/
→ Subreddit: / liveoverflow
→ Facebook: / liveoverflow

Пікірлер: 218
@oriyadid
@oriyadid Жыл бұрын
This video should be called "The origin of the same origin policy"
@vaisakhkm783
@vaisakhkm783 Жыл бұрын
but this way he will get more clicks :)
@oriyadid
@oriyadid Жыл бұрын
@@vaisakhkm783 it's a joke, obviously it's not a good title, just a bad pun
@xrafter
@xrafter Жыл бұрын
@@oriyadid I liked his Minecraft videos .
@cedricsullivan6277
@cedricsullivan6277 Жыл бұрын
The essence of genius. Most of us will never achieve galaxy brain.
@i3_13
@i3_13 Жыл бұрын
Go on, Go on.. Leave me breathless
@TheMAZZTer
@TheMAZZTer Жыл бұрын
"Did you ever install software on Windows 95?" IIRC that is an InstallShield installer (or something mimicking one). That visual style of installer was also seen back in Windows 3.11. I believe it is based off of the Windows 3.11 first run setup wizard. For the local file listings in the browser, it's worth noting even after the same origin problem was fixed, websites would still try to trick users into thinking you were vulnerable by showing you a frame with your local file listing and then trying to convince you to buy their anti-virus software to fix it. This was especially bad in IE where the local file listing was a REAL Windows File Explorer frame, as IE and the file explorer were deeply integrated then, before MS realized it was a bad idea (and they got sued over anticompetitive practices regarding IE by the EU).
@Wallee580
@Wallee580 Жыл бұрын
What an interesting comment, but scrollbar go brrr xD
@bagustesa
@bagustesa Жыл бұрын
the nice part about IE and Windows File Explorer integration was you can style a folder view using literal html, css, and javascript. that and a bunch of troubles of having wild script executing in your File Explorer.
@Valery0p5
@Valery0p5 Жыл бұрын
I think some leftovers of that file explorer integration are still visible today... Btw some of the software my dad uses still has those installshield graphics. Meh.
@TheJamesM
@TheJamesM Жыл бұрын
An old colleague of mine was very annoyed when they finally did away with the Active Desktop feature (which was kind of the last vestige of that whole webifying Windows effort). He'd set up a page with helpful shortcuts to his most-used tools and directories, and I think he even had a little textbox that did something-or-other (maybe search a directory or run a command; I forget what was possible). I think all those kinds of conveniences did eventually make their way into Windows natively, but by then he'd made the switch to Linux. Anyway, all I ever did with Active Desktop was make silly wallpapers that would react when you moved the mouse over certain elements. As for how old I am: not only do I remember InstallShield installers; I know why you can close a window by double-clicking the program icon in the top-left (which iirc even worked on Explorer windows in Vista and 7, when there was no visible icon).
@twobob
@twobob Жыл бұрын
"I can still install software on windows 95" (hides old software defensively behind back) Don't judge me
@lightblue254
@lightblue254 Жыл бұрын
This is going to turn into a really fun series, please keep doing more :D
@0okaze
@0okaze Жыл бұрын
In the 90s, the WWW was easy to understand, not the Internet, which most people don’t even understand today. Browser didn’t exist at first and I was using IRC, Usenet, mailing lists… way before any browser could be run even on big university computers.
@MittellBuurman
@MittellBuurman Жыл бұрын
The old installer brings back memories. I once was allowed to install a game in kindergarten as a 4 year old kid. Installing the game took about an hour (I clicked "previous" and "next" over and over again because I've seen my brother do it, plus I couldnt read yet). Eventually I got it installed. It's funny that the video got out today. I just picked up an old Pentium 4 HP computer with Win XP Professional.
@anteshell
@anteshell Жыл бұрын
Ah man, I laughed too much at your comment. I learned to install stuff almost the same way. Eventually I leant that "cancel" is something bad without having any idea what it means. Didn't help that English isn't even close to my own language and started in school many years after. Been fooling around and with (literally) computers since the age of 3 and started it with Win3.1. Father never let me on his DOS computer. But learnt to install stuff on Win95 in secret from my parents at 7 or 8y old. So many good memories from those times, but I'm glad I don't have to touch those anymore.
@perryuploads776
@perryuploads776 Жыл бұрын
In the early days you could just disable Javascript, because it wasn't used a lot. You could use the internet fine. Then Dynamic webpages came along with a lot of Javascript (and ActiveX for IE users) and Macromedia Flash. In these times, disabling Javascripts killed some functionality like form checking or displaying data. I am glad developers have created like noscript plugins to "filter" javasript. This should be a standard setting, browsers never gave users a granular access control with javascript. Just a ON/OFF button to use it and a console to debug. Thanks for the history lesson
@necroowl3953
@necroowl3953 Жыл бұрын
Javascript can still be very easily obfuscated
@ieatthighs
@ieatthighs Жыл бұрын
@@necroowl3953 what does it contribute to the comment above?
@Embuer
@Embuer Жыл бұрын
2:03 As a german "Live Überlauf" killed me it's so dull that it is funny 😂
@31redorange08
@31redorange08 Жыл бұрын
It's Uberlauf. And what's funny about that?
@tw11tube
@tw11tube Жыл бұрын
0:44 Joking about being able to hit ESC at the Windows password prompt is a common theme - but few people know that the Windows password actually *does* protect you in some way. There is the CryptProtectData / CryptUnprotectData function pair in the Win32 API that is used to encrypt data with a user-specific key. This key is derived from the login password. If you hit ESC at the login prompt, you can't decrypt data that was encrypted in a session that had the correct password entered. This data encryption facility is used to store SMB passwords (IIRC Windows 95 insistes on sending the logon name as user name to every SMB computer you connect to, so no SMB usernames need to be stored) and website credentials saved by Internet Explorer. Hitting ESC at the password prompt makes saving SMB passwords and storing website logins unavailable.
@DavidRockin1
@DavidRockin1 Жыл бұрын
This was a pretty good video! I'm 23, but started actually tinkering with computers/electronics & programming when I was young (~8 ish) But when I was a bit older, around 12, is when I finally got started messing around with website development. AND OOhHH BOYYY!!! Not a lot of people today remembers/knows how BAD the internet truly was even 10 years ago. So I remember spending hours stressing to get something to work in Internet Explorer 6 to 8. But Microsoft still had a large monopoly with their GARBAGE IE. It was a pain in the ass to work, because it quite literally acts like Safari. It was either behind on the standards, or it didn't implement it properly, or it just ignored it and Microsoft did their own things. But IE was an absolute security nightmare. You remember (or have seen some videos) on weird internet website history? Pretty much all those real actual virus websites, or stupid websites you see in on email chain spam mail, a lot of those pretty much effected only Internet Explorer, because of how garbage it was. You could quite literally go on some website, and they could very easily exploit some vuln and BAM you have malware. Around the same time, Smosh, was still pretty damn popular on youtube (rip good ol' days) and they posted stuff on their website. ANd my god the 12 year old me loved their website design. But one day the Google Ads on the page reloaded, and the ad on the top went white. And then I quite literally got a virus. From a fucking ad! I was obviously pissed, but I knew **JUST ENOUGH** to open task manager, found the malware software running, and I killed it, then I manually deleted the files. ANd jussttttt to be safe, I installed Avast on my shitty WIndows Vista PC lmao. But Internet Explorer was truly a very odd & strange thing. Not only did it support javascript, but it even supported VBScript/VBA (basically running Visual Basic in your browser.) Not only that, but IE had a disgustingly plugin system, and you could have Flash, Shockwave, SIlverlight, Java, ActiveX; etc, that were all basically completely different technologies, different programming languages, and things you can build different apps OR games. IE also had a bunch of even weirder shit, like it had this proprietary gross conditional comment thing, where you can surround some HTML and target a specific version of IE. Because the standards were garbage, so a website had to have a lot of CSS to format for different browsers, and different versions! The one realllyyy cool thing, but I never understood, was Internet Explorer 5, had something called HTML Components (.htc) and it was a little plaintext file of some code, that would implement behaviour of DHTML (basically the predecessor to DOM) and I recall painstakingly Googled how to get PNG images to be transparent in old IE versions; which of course those HTC files partially fixed. Side note that this video reminded me, my uncle gave me a shitty old PC, I think it only had 8 megabytes of ram. This was 2012, but it was an old hacked together PC of various old parts from the mid 90's; and I installed Windows 95) I remember installing IE 4 & then 5 on it, and trying to use the internet on it. I don't think it lasted very long, but I remember trying to see if I could use it as a server. I have no idea if anyone actually read this but, modern day website development is soo refined butter now. Everything is essentially more secure, and probably in some form of sandbox. All the scary extension/plugin stuff were ripped out. But the soul of the internet, where anyone could express themselves is long gone. Now every website looks the exact same, and now everything just feels like a gross APP... :(
@DavidRockin1
@DavidRockin1 Жыл бұрын
Also sorry for the ted talk lmao. ADHD brain go bbrrrrrttttttttttt
@Valery0p5
@Valery0p5 Жыл бұрын
Bro I feel you. It is crazy to think what we were able to do with a few MBs
@justdoeverything8883
@justdoeverything8883 Жыл бұрын
I actually enjoyed reading it. I built my first website when I was 9, I copied my older brother's code and tinkered with it, until I understood basic html. I kind of miss how simple things were back then, responsive design for multiple screen sizes killed me when I got back into dev in my 20's. Anyway, it was cool reading your post, took me back to old days! Lol
@ant-dev
@ant-dev Жыл бұрын
thank you for your enlightenment. i hope to find a few buddies in the future that would love having conversations about this kind of stuff
@madghostek3026
@madghostek3026 Жыл бұрын
I vaguely remember times when internet explorer was the thing everybody used, but at home my dad installed firefox very early. School computers though... IE everywhere even years later
@BugBountyReportsExplained
@BugBountyReportsExplained Жыл бұрын
This is soo interesting yet I'd never spend my own time researching it so thank you for spending yours!
@josh.salles
@josh.salles Жыл бұрын
I wish I could have your voice read/explain everything to me, I don't know why but I just feel more engaged when listening/watching your videos
@danieltoth8007
@danieltoth8007 Жыл бұрын
This is my favorite video from LiveOverflow. The retrospective view makes it interesting. Keep it up!
@Dygear
@Dygear Жыл бұрын
As a professional web developer, I'm ashamed to say that I simply copy and pasted the strictest origin-policy I could find. I still don't fully understand it and I hope this series will cast some light on the dark and dusty corners of the web. I do feel that the same origin policy headers are not very well explained, so I'm looking forward to getting your thoughts on them and how best to use them today. Lucky for me, I don't need and I don't want to share information across origin, so I'm absolutely fine with the restricted set that I have.
@gatty.
@gatty. Жыл бұрын
Fantastic video! That's a throw back indeed! Haha, I remember those three vertical bars when installing software, hahaha! Looking forward to your future videos for this series.
@waldowalden7379
@waldowalden7379 Жыл бұрын
This is just GOLD! Thanks for so much dedication and enthusiasm along with the teaching. I am much fan of history and computers. My nephew is studying web development and came to me asking for some directions. I inevitably ask him to study some history about computers so he can understand how things are done today! I really had fun with this video.
@pwii
@pwii Жыл бұрын
Realtek audio drivers still use the same installer with the blue background (or at least they used to in 2019 when I was installing their drivers, idk about more recent versions)
@IndustryOfMagic
@IndustryOfMagic Жыл бұрын
I am so curious to see the evolution of this. Thank you for sharing mate.
@sxmourai6897
@sxmourai6897 Жыл бұрын
There is so much questions that I wanted to ask, that it made an overflow in my memory... But I still comment for referencement. Continue like this it's amazing !
@briansciretti-informatica6721
@briansciretti-informatica6721 Жыл бұрын
That's REALLY interesting, especially for folks like me that weren't there at the time! I remember, as a tech-inclined kid, reading old newsletters by a prominent Italian IT journalist which advised to just don't use JS, Java and ActiveX. For modern standard, unthinkable 😃
@Valery0p5
@Valery0p5 Жыл бұрын
Il buon Paolo per caso? 😉
@briansciretti-informatica6721
@briansciretti-informatica6721 Жыл бұрын
@@Valery0p5 eh sì!
@istvanbarta
@istvanbarta Жыл бұрын
Beyond its interesting history and bringing back the good retro feelings, you're doing a very important thing: review the old developed, but probably still used security policies with today's hacker's eyes, because the whole concept could be outdated. Different root cause, but the log4j is a good example of how long could a vulnerability sleeps.
@bhanuvishwa4676
@bhanuvishwa4676 Жыл бұрын
This is damnnn interesting. And for aspirants like me passionate about vuln or exploit research these series are absolutely valuable content. Please please keep doing more on such details on exploits, describing patches and how they stop the exploits and ... But discussions like these on endpoints along with these web exploits could make it even helpful for lot more people.
@AaronVTooCrazzzzy
@AaronVTooCrazzzzy Жыл бұрын
Loving the series! Keep up the good work!
@sto2779
@sto2779 Жыл бұрын
Great way to explain the details from the start using Win 95.
@mgetommy
@mgetommy Жыл бұрын
This was epic. Looking forward to next episode
@syedhasan1211
@syedhasan1211 Жыл бұрын
This is an excellent video, super informative! As a creator myself, I can’t fathom how much hard work was put into this.
@attention_shopping
@attention_shopping Жыл бұрын
what a throwback in history. before these language of browser attacks -- before the internet even became a thing. what a treasure of a video
@keithmaxon9510
@keithmaxon9510 Жыл бұрын
Please continue to do these history types of videos. As an old man that started on CP/M, I love this stuff :)
@thataperson
@thataperson Жыл бұрын
This was super cool, thank you. Very excited for the next video! First time viewing the 95 installation :)
@aziztcf
@aziztcf Жыл бұрын
Love this idea for a history series, can't wait to see some SoftICE action!
@leonardocastro742
@leonardocastro742 Жыл бұрын
For me it is incredible how one can find the exact copy of a legacy program and installed in the appropriate machine. Ah, the beauty of the digital.
@_lauritz_
@_lauritz_ Жыл бұрын
Very interesting video, thank you for your efforts. I am looking forward to further videos of this series!
@romanemul1
@romanemul1 Жыл бұрын
Thanks for this "classic" kind of video.
@Liz4rdMan
@Liz4rdMan Жыл бұрын
Really interesting! Waiting for the next episode
@DementiaAcerbus
@DementiaAcerbus Жыл бұрын
Love these videos. Please keep up with the great content like this!
@np0
@np0 Жыл бұрын
Great video as always!
@user-fm7uq4fb3f
@user-fm7uq4fb3f Жыл бұрын
Netscape crash? Wonder how hard it would be to debug and exploit that by only using tools from back in the day :P
@vaisakhkm783
@vaisakhkm783 Жыл бұрын
IKR :p
@priyapepsi
@priyapepsi Жыл бұрын
sounds like it would be right up NCommander's alleyway
@LIA-52
@LIA-52 Жыл бұрын
7:04 It's a throwback for me, and I miss the 3 indicators on the left in modern installations.
@secureitmania
@secureitmania Жыл бұрын
Eagerly waiting for the "Infosec heist" web series. Your videos contain so much insightful information.
@mrdzha9519
@mrdzha9519 6 ай бұрын
wow, thank you so much, I spent so much time trying to understand client-side stuff, but after watching this video I finally understood!!
@bhagyashreekhairnar683
@bhagyashreekhairnar683 11 ай бұрын
fab absolutely fab!! watching this fun video while preparing for JS interview reminds why JS is interesting.
@MeriaDuck
@MeriaDuck Жыл бұрын
Yep installed Netscape in those days, on win95 and Linux. A 'bit' slower than shown here on a 4Mb 486.
@kosmonautofficial296
@kosmonautofficial296 Жыл бұрын
Amazing video! Thank you that is a great way to learn
@bhagyashreekhairnar683
@bhagyashreekhairnar683 11 ай бұрын
Thank you!!! for creating this video!!!
@michaeldouglas1052
@michaeldouglas1052 Жыл бұрын
Wonderful video!
@miggu
@miggu 7 ай бұрын
Excellent research.
@prodigysonhiddenforareason1239
@prodigysonhiddenforareason1239 Жыл бұрын
Thanks man!! This really helps to understand the tech itself 😁
@4c1d
@4c1d Жыл бұрын
Definitely a throwback :)
@davidlanderos5993
@davidlanderos5993 Жыл бұрын
This is great content! seriously
@dmitryvinogradov9
@dmitryvinogradov9 Жыл бұрын
What an excellent video! Thank you very much for this historical approach. And your english is very clear for me, and subtitles are useful too. English is not my native language. I hope you can understand me =)
@dmitryvinogradov9
@dmitryvinogradov9 Жыл бұрын
I am old enough to remember this lightgreen workspace. Windows 95 was on my first personal computer when i was a child. It was Pentium 120 MHz. It`s so pleasant nostalgy )
@ZmNrbnpz
@ZmNrbnpz Жыл бұрын
I love your videos! :D Every video is always exciting and motivates me to try things out :)
@pastuh
@pastuh Жыл бұрын
At school was 4 computers, I was hooked for sure ;] When DOOM game was installed.. new rules appeared.. sometimes we could see only locked doors.
@bigmistqke
@bigmistqke Жыл бұрын
Ooo nice. Hacker history, what a great concept 👍
@JuanBotes
@JuanBotes Жыл бұрын
enjoy this history , gave me great flash backs thanks \o/
@GabrielGutierrez
@GabrielGutierrez Жыл бұрын
Amazing job.
@geovajonnathacorreia559
@geovajonnathacorreia559 10 ай бұрын
OMG your video is so amazing, thank you so much
@ItIsJan
@ItIsJan Жыл бұрын
Alternative title: The origin of the same origin policy
@Maiux92
@Maiux92 Жыл бұрын
Amazing! Thanks!
@Najumulsaqib
@Najumulsaqib Жыл бұрын
Amazing. Thank you!
@semosemo3827
@semosemo3827 Жыл бұрын
great history lesson
@b.h.5950
@b.h.5950 Жыл бұрын
Hell yes, I remember this very vividly - installing "Soldier of Fortune" on my families computer (obviously I was not allowed to) whily hearing my mom unlock the front door, praying the load bars would go away before she got to the room the computer was in (they did and I did enjoy the game quite a bit).
@centreonbot8757
@centreonbot8757 Жыл бұрын
Thank you, this is weekend, I used to learn a net stuff and your video regarding security concern is the best! not like other youtuber that concert to subscribtion and join specific channel, but you just recommend to support internet archive instead again thanks!
@HarryBallsOnYa345
@HarryBallsOnYa345 Жыл бұрын
4:43 🥶 gives me chills everytime
@toxicpsion
@toxicpsion Жыл бұрын
seeing that installer wasn't a throwback, but seeing bang-path style email addresses sure was. It reminded me that last time i saw Navigator gold, i had to install trumpet winsock first...
@testizoizo7373
@testizoizo7373 Жыл бұрын
Nice video 👍
@agentzhao
@agentzhao Жыл бұрын
thanks for sharing
@wrenchl7527
@wrenchl7527 Жыл бұрын
Fun history lesson 😁😁
@vicentecoopman97
@vicentecoopman97 Жыл бұрын
men, what a great video!
@bigbooduh
@bigbooduh Жыл бұрын
My Journey on the internet started way back with windows 98 , netscape, and a 56k dial up modem, and then came Napster :) . Took 2 minutes to load an image, 30 minutes to download a song LOL.
@secureitmania
@secureitmania Жыл бұрын
Thanks!
@kamandejohn
@kamandejohn 8 ай бұрын
This is for sure my first time 😆
@DavidRockin1
@DavidRockin1 Жыл бұрын
OH boy! A new LiveOverflow?? Oh sicckkk finally something that I can actually understand!
@olillin
@olillin Жыл бұрын
Could you do a video about possible vulnerabilities in the Minecraft 1.19.1 chat signing/reporting system? I would love to know more about it from a security perspective
@Tudumanu
@Tudumanu Жыл бұрын
awesome!
@kevinwydler4405
@kevinwydler4405 Жыл бұрын
I love this!!!
@TheFTPchannel
@TheFTPchannel Жыл бұрын
Super cool 😎
@fernandosanchez6054
@fernandosanchez6054 Жыл бұрын
Thanks a lot
@krzysztoflewandowski8262
@krzysztoflewandowski8262 Жыл бұрын
its now safe to turn of your computer...loved it.
@bluesquare23
@bluesquare23 Жыл бұрын
Great video! Sounds like browsing the internet back then was the wild wild west! But yeah I'm glad the same origin policy exists. No steal my cookies hackers!
@Will-kt5jk
@Will-kt5jk Жыл бұрын
I hope you can touch on why it was ever allowed to write cookies of a different domain (when they clearly saw issues with cross-origin operations early on) - was it just for the ad industry?
@secureitmania
@secureitmania Жыл бұрын
When I play with fetch API to hack a website. I got to know that the Same-Origin Policy is a crucial web security mechanism. Really interested to know the history of Same origin policy
@jorjorwell123
@jorjorwell123 Жыл бұрын
If you’re doing older malware, can you do older viruses like CIH and Sasser? I would love to see how they worked, especially CIH
@renakunisaki
@renakunisaki Жыл бұрын
Your scientists were so concerned with whether they could, they didn't stop to think about whether they should! Perhaps if JS had a few more months of beta testing, they'd have discovered some of these issues sooner, and could have addressed them at the core instead of having to work around them later... Imagine how the web would be today if they'd thought to implement a permission model.
@Skyfox94
@Skyfox94 Жыл бұрын
It is important to remember that, not only was the community a lot smaller 27-28 years ago - there really weren't *that* many people on the internet, even less of them were capable developers but the general mindset was also different to today. The late 80s and early 90s were a time where building systems based on trust was still very much a thing. Whilst some basic security was a thing, it wasn't anything like today. Even if they had given JS some more time, it really wouldn't have changed much. Think of it this way: How long did it take Microsoft to integrate a proper anti-virus scanner into Windows? The first release of MS Security Essentials was in 2009. Way past the point where I'd say many people started going online, wouldn't you agree? Coincidentally, Windows 7 was also the release where MS finally seemed to have addressed many of the security issues that Vista only improperly addressed. The point is, sometimes things simply happen over time, not because somebody didn't think hard or long enough, but because it takes people time to figure shit out. I'm sure the designers of IPv4 are biting themselves in the arse every time they think about the address limit they were responsible for. Sure, they came up with a solution later on but you see how that turned out by looking at the adoption rate of IPv6
@danielmitre
@danielmitre Жыл бұрын
It's easy to us to say this now that we use the browser as a sandbox to access arbitrary software. Took a while even to the OS to implement those
@AnonYmous-spyonmepls
@AnonYmous-spyonmepls Жыл бұрын
@@Skyfox94 How long did it take for microsoft to integrate a proper virus scanner? We are still waiting.
@Skyfox94
@Skyfox94 Жыл бұрын
@@AnonYmous-spyonmepls Defender is quite adequate actually
@AnonYmous-spyonmepls
@AnonYmous-spyonmepls Жыл бұрын
@@Skyfox94 Well I personally bypassed it and all the others too no big deal. Also you should check out some of the research into windows defender and you will see how deeply flawed it is yourself. Sure if you are not a pro you won’t bypass it but still its not even close to being hard. It is not just a problem of defender, Microsoft handles security extremely poorly in general. Ill go even further, to me Defender is just another attack vector
@PoignantPirate
@PoignantPirate Жыл бұрын
5:21, those are two different *host* names, not different domains. Cross site cookie protections and frame/ limits would have still seen these as the same site all the way up until the mid 2000s. (And even today, some security checks for things like microphone access will see them as the same site.) It's been 25 years, but vaguely remember the earliest versions of netscape would actually prevent cookies from being read via javascript across different sites. (But there were easy ways to get around that, and IE wasn't even *trying*.)
@Valery0p5
@Valery0p5 Жыл бұрын
Poverty meant my parents still had a lot of 16 bit computers well in the 2000, so yes I remember those interfaces...
@Valery0p5
@Valery0p5 Жыл бұрын
And no internet at home till 2012/3? So yeah I ate that Windows 7 offline guide for breakfast each day when I was a toddler
@SinaAleali
@SinaAleali Жыл бұрын
0:37 window 95 had no login screen for user login. as you can see in the title of that window it was for accessing to network. I think windows added user login window for the first time in windows NT
@awesomesauce804
@awesomesauce804 Жыл бұрын
It's wild that I'm trying to break a same origin policy right now that's controlled by regex and this video pops up in my feed.
@el7440
@el7440 Жыл бұрын
XSS is like my bread and butter so its really wonderful to see its origins
@sepppl
@sepppl Жыл бұрын
Live Uberlauf. Sehr interessanter Name :D
@ZelenoJabko
@ZelenoJabko Жыл бұрын
Hans, bitte mehr of zis! Danke Schön
@vi1r
@vi1r Жыл бұрын
@primosoma
@primosoma Жыл бұрын
Yes, I remember Windows 95. I started with Windows 3.0 and the beautiful MS-DOS. My programming journey started with TSR (terminate and stay resident), do you remember that?
@Mosi19910602
@Mosi19910602 Жыл бұрын
My first own „Big Game“ was Gothic. I was confused for month how to install a game with two Disks with only one disk drive… The next lesson that i learned was that gpus are not just plug and play. Learned everything the hard way (without internet) but was only 9 years old, so im fine. Today its so much easier to get knowledge, but finding out things by your own is a unique feeling because, how will you use something the right way if you don’t understand how it works?
@wartem
@wartem Жыл бұрын
I was always told that the only thing that Java and Javascript had in common was the name, nothing else. Interesting.
@cutterboard4144
@cutterboard4144 Жыл бұрын
Back in the days i posted an image to a computer magazines (!) forum, which was pulled from another server. thing was that this server required http authentication prior to delivering the image, so when people got to the forum and klicked the thread, they were presented with an http authentication dialog from the image server. i didnt do anything evil like having my own image server with an altered http server to transmit user:pass unencrypted back to me (dunno if thats even possible or if the browsers have/had some sort of security), but it worked as intended - the computer magazines forum admins locked the image posting capability.
@hw2024
@hw2024 Жыл бұрын
this sop only applicable to frames in websites or also 2 websites opned in 2 windows of browser?
@NaamloosDev
@NaamloosDev Жыл бұрын
I was born in 99, but my parents had been using windows 98 for quite a while before we got XP so yes, I have installed software on a windows 98 PC before :)
@cowid
@cowid Жыл бұрын
At 5:21, those are hosts, not domains. The domain is the same (i.e. liveoverflow). The hostame part of the FQDN isn't.
@ome.mishra
@ome.mishra Жыл бұрын
Wow..... Old days ....... Windows 😍
@Joel-gf4zl
@Joel-gf4zl Жыл бұрын
Oh man the nostalgia...
The Origin of Cross-Site Scripting (XSS) - Hacker Etymology
14:21
LiveOverflow
Рет қаралды 49 М.
The Circle of Unfixable Security Issues
22:13
LiveOverflow
Рет қаралды 111 М.
NO NO NO YES! (50 MLN SUBSCRIBERS CHALLENGE!) #shorts
00:26
PANDA BOI
Рет қаралды 102 МЛН
Eccentric clown jack #short #angel #clown
00:33
Super Beauty team
Рет қаралды 22 МЛН
ONE MORE SUBSCRIBER FOR 6 MILLION!
00:38
Horror Skunx
Рет қаралды 14 МЛН
Маленькая и средняя фанта
00:56
Multi DO Smile Russian
Рет қаралды 5 МЛН
Computer Networking (Deepdive)
14:52
LiveOverflow
Рет қаралды 103 М.
Same Origin Policy explained | what is Same Origin policy?
9:12
The Age of Universal XSS
12:35
LiveOverflow
Рет қаралды 49 М.
100 Boys Vs 100 Girls For $500,000
16:53
MrBeast
Рет қаралды 208 МЛН
Carbon Lang… The C++ killer?
3:27
Fireship
Рет қаралды 859 М.
CSRF Introduction and what is the Same-Origin Policy? - web 0x04
10:25
How The RIDL CPU Vulnerability Was Found
25:24
LiveOverflow
Рет қаралды 121 М.
TempleOS in 100 Seconds
2:33
Fireship
Рет қаралды 1,4 МЛН
Every Computer Can Be Hacked!
21:42
LiveOverflow
Рет қаралды 123 М.
NO NO NO YES! (50 MLN SUBSCRIBERS CHALLENGE!) #shorts
00:26
PANDA BOI
Рет қаралды 102 МЛН