Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Sending multipart/form-data requests from Flash (with arbitrary headers) Aug 10 2006 07:25AM
Amit Klein (AKsecurity) (aksecurity hotpop com)
Hello lists,

In my original "Forging HTTP request headers with Flash" paper
(http://www.securityfocus.com/archive/1/441014), I mentioned forcing multipart/form-data
input format to ensure that Flash's LoadVars isn't used to forge the request.
However, there's a work-around for the attacker - usin...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus