BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: Bypassing URL Authentication and Authorization with HTTP Verb Tampering May 28 2008 10:22PM
Jim Harrison (Jim isatools org)
Interesting (and serendipitous, at that <g>).

ISA Server 2004+ allows you to configure "allowed / denied methods" in any rule for which the web proxy is involved; effectively nullifying this attack.

..of course, this requires the web devs to communicate the minimum required methods for their site ...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus