Update: Jordan and Wladimir Palant noticed it right away! (Wladimir) "Wait, last time I checked Java wasn. Back in late 2002 Microsoft implemented the httpOnly cookie flag in Internet Explorer as a way to prevent XSS cookie theft by denying JavaScript from reading document.cookie. A couple of months later I authored a paper describing an attack I called Cross-Site Tracing (XST), or XSS++ if you prefer, as a bypass httpOnly (plus added some other good stuff). XST works by taking control of a victims web browser and forcing it to send an HTTP TRACE (method) to the target web server, typically via XmlHTTPRequest (XHR). Web servers supporting TRACE respond by placing the all data received in the HTTP request (request line, headers, post data) into the response body. Here The link for this article located at Jeremiah Grossman is no longer available. . The evolution of the httpOnly cookie flag marked a key development in web security, designed to protect sensitive cookie data from client-side scripts. HttpOnly Cookie,XST Attack,Cross-Site Tracing,Cookie Theft Attack,Web Security Techniques. . LinuxSecurity.com Team
An independent network security researcher has uncovered a new way to steal the secret browser "cookies" of Web surfers with the help of Internet servers that were never intended to communicate with browser software. The exploit, described by a researcher who uses the handle "Obscure" and posted on the Eye On Security Web (EOS) site, relies on common Internet server software other than Web servers that can "echo" hijacked submissions from HTML forms.. . .. An independent network security researcher has uncovered a new way to steal the secret browser "cookies" of Web surfers with the help of Internet servers that were never intended to communicate with browser software. The exploit, described by a researcher who uses the handle "Obscure" and posted on the Eye On Security Web (EOS) site, relies on common Internet server software other than Web servers that can "echo" hijacked submissions from HTML forms. In a demonstration of the exploit, which Obscure calls the Extended HTML Form Attack, a POP3 (post office protocol) e-mail server at Ebay was used to divulge the browser cookies of users who had visited the auction giant's Web site. As delivered by some Web sites, browser cookies may contain such private information as user IDs and passwords. The link for this article located at Newsbytes is no longer available. . An independent network security researcher has uncovered a new way to steal the secret browser 'cook. independent, network, security, researcher, uncovered, steal, secret, browser, 'cook. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.