Help with referer issues in XSS
Yuping Li <[email protected]>
| Newsgroups | gmane.comp.security.websecurity,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <CAPc2ZYJs7YY3AcbhZnt3Gc5n2kuv=BomT-Cjogwu925ksvpAgw@mail.gmail.com> |
Hi, all
Suppose there is a reflect XSS vulnerability in a pop SNS, but this
site is "concerned" about security, so they check the referer field of
certain POST request to make sure that they are normal and correct. Is
it possible for me to bypass this check within javascript? It seems
that I can't set this parameter like this:
xmlHttp.setRequestHeader("Referer","http://expected.target");
It would be appreciated if someone can give me a clue.
Regards,
_______________________________________________
The Web Security Mailing List
WebSecurity RSS Feed
http://www.webappsec.org/rss/websecurity.rss
Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA
WASC on Twitter
http://twitter.com/wascupdates
[email protected]
http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org