Full Disclosure mailing list archives
Re: Re: New Web Vulnerability - Cross-Site Tracing
From: "Thor Larholm" <thor () pivx com>
Date: Thu, 23 Jan 2003 16:04:19 +0100
From: "H D Moore" <sflist () digitaloffense net> Although its definately an interesting way to compromise client-side headers, the root is the vulnerability is the XMLHTTP component's ability to act like a HTTP proxy. Client-side scripting components should only be allowed to interact with the site which served them up, otherwise you open a huge can of worms, where XSS and user-credential theft are only the squishy little ones on top.
Isn't it great then to realize that XMLHTTP, in fact, can only interact with the site which served them - exactly as you desire? The proxy features and XSS to arbitrary foreign sites examples that are demonstrated in this 'whitepaper' are merely demonstrations of already publicly known unpatched vulnerabilities in IE. They have nothing to do with any of the findings presented. http://jscript.dk/2003/1/sec/xst-reply.txt Regards Thor Larholm PivX Solutions, LLC - Senior Security Researcher Latest PivX research: Multi-vendor Game Server DDoS Vulnerability http://www.pivx.com/press_releases/mk_mk001.html _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: New Web Vulnerability - Cross-Site Tracing Jeremiah Grossman (Jan 22)
- <Possible follow-ups>
- Re: New Web Vulnerability - Cross-Site Tracing xss-is-lame (Jan 22)
- Re: New Web Vulnerability - Cross-Site Tracing Jeremiah Grossman (Jan 22)
- Re: New Web Vulnerability - Cross-Site Tracing Tim Greer (Jan 22)
- Re: New Web Vulnerability - Cross-Site Tracing Jeremiah Grossman (Jan 22)
- Re: New Web Vulnerability - Cross-Site Tracing Tim Greer (Jan 22)
- Re: New Web Vulnerability - Cross-Site Tracing Jeremiah Grossman (Jan 22)
- Re: New Web Vulnerability - Cross-Site Tracing H D Moore (Jan 23)
- Re: Re: New Web Vulnerability - Cross-Site Tracing zeno (Jan 23)
- Re: Re: New Web Vulnerability - Cross-Site Tracing Thor Larholm (Jan 23)
- RE: Re: New Web Vulnerability - Cross-Site Tracing Richard M. Smith (Jan 23)
- Re: Re: New Web Vulnerability - Cross-Site Tracing Michal Zalewski (Jan 24)
