[32950] in bugtraq
IE 5.22 on Mac Transmitting HTTP Referer from Secure Page
daemon@ATHENA.MIT.EDU (deane@deanebarker.net)
Fri Dec 26 16:55:56 2003
Date: 24 Dec 2003 16:16:09 -0000
Message-ID: <20031224161609.5063.qmail@sf-www3-symnsj.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: <deane@deanebarker.net>
To: bugtraq@securityfocus.com
Documented instance of Internet Explorer 5.22 on a Mac transmitting an HTTP Referer header from a link on a secure page (https):
http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html
This is clearly covered in the HTTP 1.1 spec (RFC 2616), Section 15.1.3, "Encoding Sensitive Information in URI's":
"Clients SHOULD NOT include a Referer header field in a (non-secure) HTTP request if the referring page was transferred with a secure protocol."