Re: A technique to mitigate cookie-stealing XSS attacks

From: David Wagner (daw@mozart.cs.berkeley.edu)
Date: 11/08/02


To: bugtraq@securityfocus.com
From: daw@mozart.cs.berkeley.edu (David Wagner)
Date: 8 Nov 2002 04:23:56 GMT

Florian Weimer wrote:
>What about HTTP headers which advise user agents to disable some
>features, e.g. read/write access to the document or parts of it via
>scripting or other Internet Explorer interfaces?

HTTP headers are arguably the wrong place, but it might make sense to
have a <NOSCRIPTS> tag that would require the browser to turn off all
scripting for the entire HTML document, or somesuch. For instance,
application-layer proxies could add such a tag to all data crossing the
firewall, and places like Hotmail prepend such a tag to all HTML-formatted
email they receive before displaying it to the user. Of course, we would
have to trust browsers to respect such a tag, but it could potentially
give a very simple, high-assurance way to turn off dangerous features.



Relevant Pages

  • Looking for source preservation features in XML libs
    ... I'm looking for two specific features in XML libraries. ... able to tell which source file line a tag starts and ends. ... that unmodified tags preserve the original identation. ...
    (comp.lang.python)
  • selecting an option from a combo box
    ... I am a novice to VB scripting and front page, ... I created a select tag and added several options to it ... Please advice. ...
    (microsoft.public.frontpage.programming)
  • End tags in HTML
    ... I was under the impression that one of the features of HTML was that ... and HTML use a forward slash, not a back slash, to indicate an end ... Has either of these ever used a backslash in an end tag? ...
    (comp.programming)
  • Re: strange formatting with forms
    ... The tag has a tendancy to put a blank line in places you don't want. ... well (and I need to use 2 seperates forms for scripting purposes)... ... I am not familiar at all with forms, and I just started with css. ...
    (alt.html)

Quantcast