TRACE used to increase the dangerous of XSS.

From: Jeremiah Grossman (jeremiahat_private)
Date: Wed Jan 22 2003 - 12:32:58 PST

  • Next message: Lars Eilebrecht: "[ANNOUNCE] Apache 2.0.44 Released"

    WhiteHat Security has released a new white paper discussing a new class
    of web-app-sec attack (XST) which potentially affects all web servers
    supporting TRACE.
    
    The white paper explains all the detailed technical results we have
    found so far. We are fairly certain this particular issue will spark
    much debate and encourage those interested to read and comment.
    
    
    White Paper Mirrors:
    http://www.betanews.com/whitehat/WH-WhitePaper_XST_ebook.pdf
    http://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdf
    http://www.boarder.org/WH-WhitePaper_XST_ebook.pdf
    http://www.forumgalaxy.com/whmirror/WhitePaper_screen.pdf
    
    Press Release
    http://www.whitehatsec.com/press_releases/WH-PR-20030120.txt
    



    This archive was generated by hypermail 2b30 : Wed Jan 22 2003 - 18:05:28 PST