OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-disclosure] Referers Are Evil

From: Tim (tim-securitysentinelchicken.org)
Date: Sun Aug 07 2005 - 16:42:35 CDT


> What if regular users are behind rotating proxies (e.g., AOL)? :-)

...or on the same network with NAT.

...or on the same network segment with no NAT... steal cookie, the
proceed to steal the victim's IP with ARP poisoning...

tim
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/