- evil.com:
<script>
----πͺ----> facebook.com/π€.csv- fix: opaque response
- evil.com:
<script>
----π----> go/π€.csv- fix: opaque response
- evil.com:XHR:X-Data --πͺ--> facebook.com/π€.json
- fix: drop response (unless CORS headers opt in)
- evil.com:XHR:X-Patriot --πͺ-> us.mil/π
- fix: preflight
- evil.com:
@font-face
---------> cdn.com/π°.woff- fix: drop response (unless CORS headers opt in)
- evil.com:
<a>
-------πͺ------> bank.com/π- fix: no side effects through GET
- evil.com:
<form>
-----πͺ-----> bank.com/π- fix: session token
- πͺ - cookie (authentication)
- π - intranet IP address
- π€ - secret data
- π - side effect
- π° - copyrighted asset