|
BugTraq
RE: A technique to mitigate cookie-stealing XSS attacks Nov 13 2002 11:10PM Steven M. Christey (coley linus mitre org) (2 replies) RE: A technique to mitigate cookie-stealing XSS attacks Nov 14 2002 03:57PM Eric Stevens (mightye mightye org) |
|
Privacy Statement |
> Being able to place arbitrary HTML into an intermediate web page is
> dangerous for other reasons (this is sometimes called "HTML
> injection," but I view it as another flavor of XSS). For example,
> this would allow attackers to use META-REFRESH style attacks to
> redirect victims away from the intended web site.
..or to redirect victims to a script on the intended web site that does
something (i e, sending mails or posting Usenet messages under the
victim's name). It's not just about stealing cookies.
// Ulf Harnhammar
VSU Security
ulfh (at) update.uu (dot) se [email concealed]
[ reply ]