Hacker News new | ask | show | jobs
by foxylion 2449 days ago
You can also just do a normal form post request into an invisible iframe that is generated by the attacker's javascript.