Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: TRACE used to increase the dangerous of XSS.

From: Jeremiah Grossman <jeremiah(at)whitehatsec.com>
Date: Wed Jan 22 2003 - 21:57:11 EST

On Wed, 2003-01-22 at 17:45, Jordan Frank wrote:
> Damnit, can't peg this one on microsoft...

hehe, the agony! :)

>
> I initially wanted to post some message to the mailing lists talking about

in XMLHTTP there is no way we have found to access the HTTP Request Headers before they are sent to the server. Set the headers sure, but thats it.

As far are getting headers...we could only get the HTTP Response Headers

XMLHTTP Properties reference.
http://www.devguru.com/Technologies/xmldom/quickref/obj_httpRequest.html

 If you can show me another way to get the authentication
> information from the client through javascript then please let me know

Do you need help?X

me too.

>
> Anyways, props to WhiteHat Security for sharing their findings. This adds

thank you. Received on Wed Jan 22 23:18:15 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:47 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library