Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-disclosure] Firefox: serious cookie stealing / same-domain bypass vulnerability Feb 22 2007 01:08AM
Michal Zalewski (lcamtuf dione ids pl)
There seems to be some confusion regarding the exact impact of the
location.hostname vulnerability, and the ways to protect against it. I
wanted to offer a quick clarification.

1) Cookie setting (session fixation) attacks can be executed universally
and with no restrictions. This is demonstr...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus