|
|||||||||||
|
RE: TRACE used to increase the dangerous of XSS.
From: Jeremiah Grossman <jeremiah(at)whitehatsec.com>
Date: Wed Jan 22 2003 - 18:35:08 EST
On Wed, 2003-01-22 at 14:34, Richard M. Smith wrote:
you might correct...and then it might both NS and IE. Although...if we call it a browser bug and fix it there... we are relying on client-side security to ensure the integrity of the cookies on the target domain. Much easier for a web server admin to simply deny trace. At least that was our take after talking to everyone we could. In the end...we outline several points of weakness in the paper to which we recommend solutions.
Shouldn't the Microsoft XMLHTTP
Thats really not my call on if that SHOULD be done or not. Or maybe it would break some functionality. It would certainly help.
I know that this already happens when a GET or a
Really?... I must test. >
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:47 EDT |
||||||||||
|
|||||||||||