[VulnDiscuss] RE: TRACE used to increase the dangerous of XSS.

Jeremiah Grossman <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq,gmane.comp.security.web-applications
Message-ID <[email protected]>
On Wed, 2003-01-22 at 14:34, Richard M. Smith wrote:
> Isn't this a bug in Internet Explorer?  

you might correct...and then it might both NS and IE. Although...if we
call it a browser bug and fix it there... 

we are relying on client-side security to ensure the integrity of the
cookies on the target domain. Much easier for a web server admin to
simply deny trace.

At least that was our take after talking to everyone we could.

In the end...we outline several points of weakness in the paper to which
we recommend solutions.


Shouldn't the Microsoft XMLHTTP
> ActiveX control be removing cookies from returned HTTP headers when a
> HTTP TRACE is done?  

Thats really not my call on if that SHOULD be done or not. Or maybe it
would break some functionality. It would certainly help.


I know that this already happens when a GET or a
> POST is done with XMLHTTP.


Really?... I must test.




> 
> Richard M. Smith
> http://www.ComputerBytesMan.com
> 
> -----Original Message-----
> From: Jeremiah Grossman [mailto:[email protected]] 
> Sent: Wednesday, January 22, 2003 3:33 PM
> To: [email protected]; [email protected];
> [email protected]
> Subject: TRACE used to increase the dangerous of XSS.
> 
> 
> WhiteHat Security has released a new white paper discussing a new class
> of web-app-sec attack (XST) which potentially affects all web servers
> supporting TRACE.
> 
> The white paper explains all the detailed technical results we have
> found so far. We are fairly certain this particular issue will spark
> much debate and encourage those interested to read and comment.
> 
> 
> White Paper Mirrors:
> http://www.betanews.com/whitehat/WH-WhitePaper_XST_ebook.pdf
> http://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdf
> http://www.boarder.org/WH-WhitePaper_XST_ebook.pdf
> http://www.forumgalaxy.com/whmirror/WhitePaper_screen.pdf
> 
> Press Release
> http://www.whitehatsec.com/press_releases/WH-PR-20030120.txt
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.