Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Bypassing URL Authentication and Authorization with HTTP Verb Tampering May 28 2008 07:28PM
Arshan Dabirsiaghi (arshan dabirsiaghi aspectsecurity com)
Internetizens,

Many URL authentication and authorization mechanisms make security
decisions based on the HTTP verb in the request. Many of these
mechanisms work in a counter-intuitive way. This fact, in combination
with some oddities in the way that both web and application servers
handle unexpecte...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus