Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: "Divide and Conquer" - cross site response header tampering, cookie manipulation, and session fixation Mar 07 2004 11:02AM
Amit Klein (amit klein sanctuminc com)
Hi Peter,

Thanks for your message.

I would like to make a distinction here. The attack I described, HTTP
Response Splitting (or Divide and Conquer), is mostly focused on
crafting an entire new HTTP response message. The direction described
below is manipulation of the HTTP response in such way ...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus