[VulnWatch] TRACE used to increase the dangerous of XSS.

From: Jeremiah Grossman (jeremiah@whitehatsec.com)
Date: 01/22/03

  • Next message: Rain Forest Puppy: "[VulnWatch] administrivia: cross-site tracing"
    From: Jeremiah Grossman <jeremiah@whitehatsec.com>
    To: bugtraq@securityfocus.com, webappsec@securityfocus.com, "vulnwatch@vulnwatch.org" <vulnwatch@vulnwatch.org>
    Date: 22 Jan 2003 12:32:58 -0800
    
    

    WhiteHat Security has released a new white paper discussing a new class
    of web-app-sec attack (XST) which potentially affects all web servers
    supporting TRACE.

    The white paper explains all the detailed technical results we have
    found so far. We are fairly certain this particular issue will spark
    much debate and encourage those interested to read and comment.

    White Paper Mirrors:
    http://www.betanews.com/whitehat/WH-WhitePaper_XST_ebook.pdf
    http://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdf
    http://www.boarder.org/WH-WhitePaper_XST_ebook.pdf
    http://www.forumgalaxy.com/whmirror/WhitePaper_screen.pdf

    Press Release
    http://www.whitehatsec.com/press_releases/WH-PR-20030120.txt



    Relevant Pages

    • Re: Scalable .NET?
      ... You might want to read up on this (sort of white paper): ... > additional web servers. ... > article that describes such architecture? ...
      (microsoft.public.dotnet.general)
    • TRACE used to increase the dangerous of XSS.
      ... WhiteHat Security has released a new white paper discussing a new class ... of web-app-sec attack which potentially affects all web servers ... supporting TRACE. ...
      (Bugtraq)
    • Scalable .NET?
      ... i.e. to address future load requirements, we'd like to be able to simply add ... additional web servers. ... Does anyone know of a White Paper or other ... article that describes such architecture? ...
      (microsoft.public.dotnet.general)