[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bugtraq
Subject:    RE: "Exploiting the XmlHttpRequest object in IE" - paper by Amit Klein
From:       "Sergey V. Gordeychik" <gordey () itsecurity ! ru>
Date:       2005-09-30 6:00:55
Message-ID: C5AD85826306B14CBB3DA801643F987B02A1AD0B () nt_server ! infosec ! ru
[Download RAW message or body]

Hi list.

I checked some ideas and think that reflected XSS in user-agent and
other http request headers fileds (cookies for example) can be exploited
via http request smuggling\splitting cache poisoning attacks using
described techniques.
So vendors who discard such vulnerabilities as not explotable should
take it into account. 

Regards,
Sergey V. Gordeychik,
MCSE, MCT, CISSP
 

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic