Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




webappsec logo WebApp Sec mailing list archives

Re: Whitepaper "SESSION RIDING - A Widespread Vulnerability in Today's Web Applications"
From: Florian Weimer <fw () deneb enyo de>
Date: Wed, 22 Dec 2004 19:09:52 +0100

Not such a good idea.  The referer value is no more trustworthy than
anything else supplied by the client.

Can the Refer: header be changed using JavaScript, on the common
browsers?  If not, we can use it (as long as it's available) because
it provides the attestation we need.

The trouble with the Referer: header is that it's often filtered for
privacy reasons, and not available in some case (as mentioned in the
paper, this happens when an HTML message is displayed by a mail user
agent).


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]