|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: recent 'cross site scripting' CERT advisory
From: Ari Gordon-Schlosberg (regs
NEBCORP.COM)Date: Mon Feb 07 2000 - 17:55:00 CST
- Next message: Kelly.Setzer
INGRAMENTERTAINMENT.COM: "DBI bind values [was Re: RFP2K01 - "How I hacked Packetstorm" (wwwthreads advisory)]"
- Previous message: NAI Labs: "SCO OpenServer SNMPD vulnerability"
- In reply to: Bill Thompson: "Re: recent 'cross site scripting' CERT advisory"
- Next in thread: Taneli Huuskonen: "Re: recent 'cross site scripting' CERT advisory"
- Next in thread: Marc Slemko: "Re: recent 'cross site scripting' CERT advisory"
- Reply: Ari Gordon-Schlosberg: "Re: recent 'cross site scripting' CERT advisory"
- Reply: Taneli Huuskonen: "Re: recent 'cross site scripting' CERT advisory"
- Reply: Henri Torgemane: "Re: recent 'cross site scripting' CERT advisory"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Bill Thompson <bill
DIAL.PIPEX.COM>]
> One form of protection from a truly *cross-site* attack that I didn't
> see mentioned in the CERT advisory is the trusty "HTTP_REFERER"
> check. But then, with so many sites using affiliate programs to get
> their search boxes and book-buying links distributed across the Web,
> there may be few major e-commerce sites that block requests based on
> the referral source.
HTTP_REFERER is trivial to spoof, and it's likely that anyone perpetrating
a sophisticated attack would laugh at having to spoof the Referer: header.
It's a form of trusting the client, which is a big, huge, no-no. It's okay
if you're trying to protect from someone seeing a page that should
register for (like downloading a white paper), because it's not worth an
attackers trouble to circumvent something like. But Referer: should never
be used as a security measure. Hell, anyone with telnet can spoof a Refer:
URL.
-- Ari there is no spoon ------------------------------------------------------------------------- http://www.nebcorp.com/~regs/pgp for PGP public key
- Next message: Kelly.Setzer
INGRAMENTERTAINMENT.COM: "DBI bind values [was Re: RFP2K01 - "How I hacked Packetstorm" (wwwthreads advisory)]"
- Previous message: NAI Labs: "SCO OpenServer SNMPD vulnerability"
- In reply to: Bill Thompson: "Re: recent 'cross site scripting' CERT advisory"
- Next in thread: Taneli Huuskonen: "Re: recent 'cross site scripting' CERT advisory"
- Next in thread: Marc Slemko: "Re: recent 'cross site scripting' CERT advisory"
- Reply: Ari Gordon-Schlosberg: "Re: recent 'cross site scripting' CERT advisory"
- Reply: Taneli Huuskonen: "Re: recent 'cross site scripting' CERT advisory"
- Reply: Henri Torgemane: "Re: recent 'cross site scripting' CERT advisory"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]