IE 5.22 on Mac Transmitting HTTP Referer from Secure Page

deane_at_deanebarker.net
Date: 12/24/03

  • Next message: n.teusink_at_planet.nl: "OpenBB 1.06 SQL Injection"
    Date: 24 Dec 2003 16:16:09 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Documented instance of Internet Explorer 5.22 on a Mac transmitting an HTTP Referer header from a link on a secure page (https):

    http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html

    This is clearly covered in the HTTP 1.1 spec (RFC 2616), Section 15.1.3, "Encoding Sensitive Information in URI's":

    "Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol."


  • Next message: n.teusink_at_planet.nl: "OpenBB 1.06 SQL Injection"

    Relevant Pages

    • Re: is that a good offer for a server installation?
      ... SO linux based upon kernel 2.6xx ... installation of cwfm (a software that manages files, at first I believed that should be created by them, but then I found out to be free on the net http://cwfm.sourceforge.net) upload and download are managed via http ... they told him that ftp is not secure for this and their program is based ... they use a https connection then it should be secure enough. ...
      (comp.infosystems.www.servers.unix)
    • Re: Encrypted or Not Encrypted
      ... Optimally they should enter their creds after ssl has setup the secure session, ... The handshake requires that the client initiate the SSL connection. ... The agent acting as the HTTP client should also act as the TLS ...
      (Security-Basics)
    • Re: Help, my machine has been hacked
      ... > being used to perform port scans on a bank. ... > closed HTTP) ... > DSLReports and they all report that my machine is secure. ... > 4) Recommendations for a hardware firewall? ...
      (comp.os.linux.security)
    • Re: Rule Schedule
      ... possible to restrict HTTP & HTTPS traffic to use only webproxy and not ... Deny Yahoo ... Deny MSN ... the secure nat session established during the allowed ...
      (microsoft.public.isa)
    • Re: Cain & Able man in the middle attack
      ... successful I now need to secure my self against these attacks but how ... what http and ftp passwords are crossing ... Need to secure your web apps NOW? ...
      (Pen-Test)