|
|||||||||||
|
RE: TRACE used to increase the dangerous of XSS.
From: Jeremiah Grossman <jeremiah(at)whitehatsec.com>
Date: Wed Jan 22 2003 - 21:28:15 EST
On Wed, 2003-01-22 at 18:06, Richard M. Smith wrote:
thank you. I appreciate it. > However, XMLHTTP ActiveX control shouldn't support the TRACE method.
Hmm maybe, maybe not. Been thinking about this a lot as you can imagine.:) Denying the simple TRACE method from XMLHTTP would certainly mitigate many issues instantly. Or at least marking that control not safe for scripting would help as well. However XMLHTTP isnt the only Active HTTP API. There are also other client-side technologies that could potentially yield the same power as XMLHTTP and perform the attack as well. Like Java, Flash, or anything else with access over HTTP. I havent 100% confirmed HTTP control within Flash or Java from the browser, but I think their Macromedia's new stuff is really powerful at the HTTP protocol level. > XMLHTTP already removes incoming cookies and doesn't allow JavaScript to
That very interesting that they do that actually. Wouldnt have guessed it beforehand. Received on Wed Jan 22 23:14:06 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:47 EDT |
||||||||||
|
|||||||||||