Re: [VulnDiscuss] Re: TRACE used to increase the dangerous of XSS.
"Kevin Spett" <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <00aa01c2c30d$c185ae70$180a10ac__31474.1752496504$1043350363@spidynamics.com> |
> I am not familiar with any HTTP aware network based firewalls which have > the ability to see inside of an HTTP request looking for TRACE and then > deny. Likely because its too much overhead per request. But hey, I could > be wrong, maybe there is one. Reverse proxy servers could probably do this pretty easily. Kevin Spett SPI Labs http://www.spidynamics.com/