Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: TRACE used to increase the dangerous of XSS. Jan 23 2003 09:10AM
Thor Larholm (thor pivx com)
I just finished reading this so-called whitepaper and the press release, and
all I can say is hyped, sensationalised snakeoil.

The HttpOnly cookie feature, a proprietary Microsoft extension designed to
mitigate a single aspect of XSS, can be circumvented in myriads of ways. In
fact, reading the HTT...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus