[40547] in bugtraq

home help back first fref pref prev next nref lref last post

RE: "Exploiting the XmlHttpRequest object in IE" - paper by Amit Klein

daemon@ATHENA.MIT.EDU (Sergey V. Gordeychik)
Fri Sep 30 17:00:42 2005

Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Date: Fri, 30 Sep 2005 10:00:55 +0400
Message-ID: <C5AD85826306B14CBB3DA801643F987B02A1AD0B@nt_server.infosec.ru>
From: "Sergey V. Gordeychik" <gordey@itsecurity.ru>
To: <bugtraq@securityfocus.com>, <full-disclosure@lists.grok.org.uk>
Content-Transfer-Encoding: 8bit

Hi list.

I checked some ideas and think that reflected XSS in user-agent and
other http request headers fileds (cookies for example) can be exploited
via http request smuggling\splitting cache poisoning attacks using
described techniques.
So vendors who discard such vulnerabilities as not explotable should
take it into account. 

Regards,
Sergey V. Gordeychik,
MCSE, MCT, CISSP
 

home help back first fref pref prev next nref lref last post