[Full-disclosure] RE: Cross Site Cooking



On Sun, 29 Jan 2006, Amit Klein (AKsecurity) wrote:

> I tried setting a cookie for .com.pl, and I failed (that is, the browser
> did not respect it). If you set a cookie for .kom.pl, it will be OK (if
> you're in .kom.pl domain, that is).

Amit,

Mozilla/Firefox/Netscape are vulnerable to this flaw (and probably so is
Konqueror). You are right in regard to MSIE 6, however - my apologies.

I tested the vulnerability with *.com.pl for Firefox, and then followed up
with a quicker test for *.ids.pl with MSIE, assuming it wouldn't implement
such a kludge - my bad.

So, to sum up - the first bug applies to Mozilla-based browsers, but not
to MSIE; the other two bugs apply to all browsers.

/mz
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • RE: Cross Site Cooking
    ... On Sun, 29 Jan 2006, Amit Klein wrote: ... If you set a cookie for .kom.pl, ... You are right in regard to MSIE 6, ... So, to sum up - the first bug applies to Mozilla-based browsers, but not ...
    (Bugtraq)
  • Re: Javascript Best Practices Document v1.0
    ... Especially when there are hundreds of links on a page, having each one contain a useless href is pointless, when the user is known to have javascript enabled. ... If your goal is to support modern browsers, then why do you need to detect the support for getElementById? ... You gave examples and a how-to to support MSIE 4.x in your 1st draft of your document and I still see that in your fallback recommendation for that unique particular browser version. ...
    (comp.lang.javascript)
  • Re: WWW-Authenticate: How to force password login at every page refresh ?
    ... > How can I force the page to prompt for a password at every refresh? ... Browsers are designed to work like this so people don't need to ... is use this in combination with a cookie. ... password then you know this is the second request, ...
    (comp.lang.php)
  • [Full-disclosure] Compromising pictures of Microsoft Internet Explorer!
    ... to report on a casual 30-minute experiment I've conducted of recent. ... You might remember the 'mangleme' affair, where various browsers were ... MSIE performed admirably compared to other browsers (although ... unless code execution path can be affected later on. ...
    (Full-Disclosure)
  • Re: Browser DNS balancing effects
    ... curl's cookie support. ... I notice the DNS entry for the ... It could be that my curl requests are hitting a different server each time, ... So what I wondered is how do browsers handle the case of multiple A records? ...
    (uk.comp.os.linux)