sintaxi / surge

CLI for the surge.sh CDN
https://surge.sh
2.85k stars 136 forks source link

please submit surge.sh to the Public Suffix List #361

Open dkg opened 5 years ago

dkg commented 5 years ago

since subdomains to surge.sh can include arbitrary javascript, it's possible for evil.surge.sh to steal a cookie from baby.surge.sh, or to perform session fixation attacks, cross-site request forgeries, etc.

I recommend adding surge.sh to the Public Suffix List to avoid letting different subdomains attack other subdomains via the browser's same origin policy.