Podlipodcast player Webplayer

CyberCode Academy

CyberCode Academy

Course 38 - Web Security Known Web Attacks | Episode 5: SOP Fundamentals and SOME Attack Exploitation via Flash Callbacks

CyberCode Academy · Jul 6, 2026 · 25:19

0:0025:19

Listen in the Podli app 🎧

Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.

In this lesson, you’ll learn about: Same Origin Policy (SOP), its controlled exceptions, and how attackers exploit it using SOME via Flash callbacks1. What is the Same Origin Policy (SOP)🔹 Definition:🔹 Enforced in:🔹 Rule:
Two URLs can interact only if all match:👉 Key Insight
SOP prevents unauthorized access between different websites2. Why SOP Exists🔹 Purpose:🔹 Without SOP:👉 Key Insight
SOP is the foundation of web security isolation3. Soft Exclusions to SOP🔹 Allowed interactions:🔹 Why they exist:👉 Key Insight
SOP is strict—but not absolute4. Introducing SOME (Same Origin Method Execution)🔹 Definition:🔹 Related concept:👉 Key Insight
SOME doesn’t break SOP—it works around it5. Role of Flash in SOME Attacks🔹 Technology involved:🔹 Bridge:🔹 Key function:👉 Key Insight
Flash acts as a bridge to execute JS indirectly6. How Flash Callbacks Become Vulnerable🔹 Weakness:🔹 Restrictions:🔹 Still dangerous because:👉 Key Insight
Limited input ≠ safe input7. SOME Attack Lifecycle🔹 Step-by-step:
  1. Victim visits attacker page
  2. Malicious page opens new tab
  3. Uses window.opener reference
  4. Parent tab redirected to target site
  5. Payload executes via callback
👉 Key Insight
Attack uses tab relationships + timing8. DOM Manipulation via SOME🔹 Target:🔹 What attacker can do:👉 Key Insight
User actions are simulated without consent9. Real-World Example: WordPress Exploit🔹 Platform:🔹 Vulnerability:🔹 Attack outcome:👉 Key Insight
Even mature platforms can have legacy weak points10. Bypassing Filters🔹 Challenge:🔹 Solution:👉 Key Insight
Attackers reuse existing trusted functions11. Chaining Actions🔹 Advanced technique:🔹 Result:👉 Key Insight
Simple actions can be chained into full compromise12. Why SOME is Powerful🔹 Works when:🔹 Because:👉 Key Insight
Security controls can be bypassed via unexpected paths13. How to Prevent SOME Attacks🔹 Remove legacy risks:🔹 Secure callbacks:🔹 Protect windows:👉 Key Insight
Modern security = eliminate legacy + validate everything14. Big PictureYou are learning:👉 How SOP protects—but also limits
👉 How attackers abuse allowed behaviors
👉 Why legacy tech (Flash) is dangerousMental ModelSOP restriction → allowed exceptions → weak callback → window reference → method execution → silent attack

You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy

Episodes: CyberCode Academy

PodliGet the free Podli app
↓ App