Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: TRACE used to increase the dangerous of XSS.

From: Jeremiah Grossman <jeremiah(at)whitehatsec.com>
Date: Wed Jan 22 2003 - 18:35:08 EST

On Wed, 2003-01-22 at 14:34, Richard M. Smith wrote:
> Isn't this a bug in Internet Explorer?

you might correct...and then it might both NS and IE. Although...if we call it a browser bug and fix it there...

we are relying on client-side security to ensure the integrity of the cookies on the target domain. Much easier for a web server admin to simply deny trace.

At least that was our take after talking to everyone we could.

In the end...we outline several points of weakness in the paper to which we recommend solutions.

Shouldn't the Microsoft XMLHTTP
> ActiveX control be removing cookies from returned HTTP headers when a

Thats really not my call on if that SHOULD be done or not. Or maybe it would break some functionality. It would certainly help.

Do you need help?X

I know that this already happens when a GET or a
> POST is done with XMLHTTP.

Really?... I must test.

>
> Richard M. Smith
> http://www.ComputerBytesMan.com
Received on Wed Jan 22 19:58:18 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:47 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library