[Full-disclosure] RE: "Exploiting the XmlHttpRequest object in IE" - paper by Amit Klein
From: Sergey V. Gordeychik (gordey_at_itsecurity.ru)
Date: 09/30/05
- Previous message: Martin Schulze: "[Full-disclosure] [SECURITY] [DSA 831-1] New mysql-dfsg packages fix arbitrary code execution"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 30 Sep 2005 10:00:55 +0400 To: <bugtraq@securityfocus.com>, <full-disclosure@lists.grok.org.uk>
Hi list.
I checked some ideas and think that reflected XSS in user-agent and
other http request headers fileds (cookies for example) can be exploited
via http request smuggling\splitting cache poisoning attacks using
described techniques.
So vendors who discard such vulnerabilities as not explotable should
take it into account.
Regards,
Sergey V. Gordeychik,
MCSE, MCT, CISSP
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Previous message: Martin Schulze: "[Full-disclosure] [SECURITY] [DSA 831-1] New mysql-dfsg packages fix arbitrary code execution"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|