BugTraq
A technique to mitigate cookie-stealing XSS attacks Nov 05 2002 06:44PM
Michael Howard (mikehow microsoft com) (3 replies)
Re: A technique to mitigate cookie-stealing XSS attacks Nov 11 2002 06:19PM
Jeremiah Grossman (jeremiah whitehatsec com) (1 replies)
RE: A technique to mitigate cookie-stealing XSS attacks Nov 12 2002 12:46AM
Jason Coombs (jasonc science org)
Re: A technique to mitigate cookie-stealing XSS attacks Nov 07 2002 08:26PM
Justin King (justin othius com) (1 replies)
Re: A technique to mitigate cookie-stealing XSS attacks Nov 10 2002 03:21AM
Ulf Harnhammar (ulfh update uu se) (2 replies)
RE: A technique to mitigate cookie-stealing XSS attacks Nov 12 2002 10:43AM
jasonk (jasonk swin edu au)
Re: A technique to mitigate cookie-stealing XSS attacks Nov 11 2002 08:29PM
Seth Arnold (sarnold wirex com)
Re: A technique to mitigate cookie-stealing XSS attacks Nov 05 2002 09:38PM
Florian Weimer (Weimer CERT Uni-Stuttgart DE) (2 replies)
"Michael Howard" <mikehow (at) microsoft (dot) com [email concealed]> writes:

> In a nutshell, if Internet Explorer 6.0 SP1 detects a cookie that has a
> trailing HttpOnly (case insensitive) it will return an empty string to
> the browser when accessed from script, such as by using document.cookie.

What about HTTP headers which advise user agents to disable some
features, e.g. read/write access to the document or parts of it via
scripting or other Internet Explorer interfaces?

Is anybody interested in writing an Informational RFC on this topic?

--
Florian Weimer Weimer (at) CERT.Uni-Stuttgart (dot) DE [email concealed]
University of Stuttgart http://CERT.Uni-Stuttgart.DE/people/fw/
RUS-CERT fax +49-711-685-5898

[ reply ]
Re: A technique to mitigate cookie-stealing XSS attacks Nov 08 2002 04:23AM
daw mozart cs berkeley edu (David Wagner)
Re: A technique to mitigate cookie-stealing XSS attacks Nov 06 2002 05:16AM
Valdis Kletnieks vt edu (1 replies)
Re: A technique to mitigate cookie-stealing XSS attacks Nov 08 2002 10:12AM
Florian Weimer (Weimer CERT Uni-Stuttgart DE)


 

Privacy Statement
Copyright 2010, SecurityFocus