Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: TRACE used to increase the dangerous of XSS.

From: Jeremiah Grossman <jeremiah(at)whitehatsec.com>
Date: Wed Jan 22 2003 - 21:28:15 EST

On Wed, 2003-01-22 at 18:06, Richard M. Smith wrote:
> This is a very cool find by Jeremiah.

thank you. I appreciate it.

> However, XMLHTTP ActiveX control shouldn't support the TRACE method.

Hmm maybe, maybe not. Been thinking about this a lot as you can imagine.:)

Denying the simple TRACE method from XMLHTTP would certainly mitigate many issues instantly. Or at least marking that control not safe for scripting would help as well. However XMLHTTP isnt the only Active HTTP API. There are also other client-side technologies that could potentially yield the same power as XMLHTTP and perform the attack as well.

Like Java, Flash, or anything else with access over HTTP. I havent 100% confirmed HTTP control within Flash or Java from the browser, but I think their Macromedia's new stuff is really powerful at the HTTP protocol level.  

> XMLHTTP already removes incoming cookies and doesn't allow JavaScript to

Do you need help?X

That very interesting that they do that actually. Wouldnt have guessed it beforehand. Received on Wed Jan 22 23:14:06 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:47 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library