IE 5.22 on Mac Transmitting HTTP Referer from Secure Page
deane_at_deanebarker.net
Date: 12/24/03
- Previous message: Zero_X www.lobnan.de Team: "Remote Code Execution in Knowledge Builder."
- Next in thread: tlarholm_at_pivx.com: "RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page"
- Maybe reply: tlarholm_at_pivx.com: "RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 24 Dec 2003 16:16:09 -0000 To: bugtraq@securityfocus.com('binary' encoding is not supported, stored as-is)
Documented instance of Internet Explorer 5.22 on a Mac transmitting an HTTP Referer header from a link on a secure page (https):
http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html
This is clearly covered in the HTTP 1.1 spec (RFC 2616), Section 15.1.3, "Encoding Sensitive Information in URI's":
"Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol."
- Previous message: Zero_X www.lobnan.de Team: "Remote Code Execution in Knowledge Builder."
- Next in thread: tlarholm_at_pivx.com: "RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page"
- Maybe reply: tlarholm_at_pivx.com: "RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|