Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: RE: Cross Site Cooking

RE: Cross Site Cooking

From: Michal Zalewski <lcamtuf_at_dione.ids.pl>
Date: Mon, 30 Jan 2006 11:02:02 +0100 (CET)

On Sun, 29 Jan 2006, Amit Klein (AKsecurity) wrote:

> I tried setting a cookie for .com.pl, and I failed (that is, the browser
> did not respect it). If you set a cookie for .kom.pl, it will be OK (if
> you're in .kom.pl domain, that is).

Amit,

Mozilla/Firefox/Netscape are vulnerable to this flaw (and probably so is
Konqueror). You are right in regard to MSIE 6, however - my apologies.

I tested the vulnerability with *.com.pl for Firefox, and then followed up
with a quicker test for *.ids.pl with MSIE, assuming it wouldn't implement
such a kludge - my bad.

So, to sum up - the first bug applies to Mozilla-based browsers, but not
to MSIE; the other two bugs apply to all browsers.

/mz

-------------------------------------------------------------------------
This List Sponsored by: Watchfire

Watchfire's AppScan is the industry's first and leading web application
security testing suite, and the only solution to provide comprehensive
remediation tasks at every level of the application. See for yourself.
Download AppScan 6.0 today.

https://www.watchfire.com/securearea/appscansix.aspx?id=701300000003Ssh
--------------------------------------------------------------------------
Received on Jan 30 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]