http://blog.portswigger.net/2016/11/json-hijacking-for-modern-web.html Also contains other helpful hints too