|
Re: "Exploiting the XmlHttpRequest object in IE" - paper by Amit Klein: msg#00020security.websecurity
Amit Klein (AKsecurity) wrote: The problem with images, and how it can be solved Wouldn't this be easily prevented if www.target.site were to included a "Vary: Referer" header in its response? I think it can even reasonably be argued that this is recommended behavior according to RFC 2616 (Hypertext Transfer Protocol - HTTP/1.1): "An HTTP/1.1 server SHOULD include a Vary header field with any cacheable response that is subject to server-driven negotiation." http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html#sec14.44 Bob |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | "Exploiting the XmlHttpRequest object in IE" - paper by Amit Klein: 00020, Amit Klein (AKsecurity) |
|---|---|
| Next by Date: | Re: "Exploiting the XmlHttpRequest object in IE" - paper by Amit Klein: 00020, Amit Klein (AKsecurity) |
| Previous by Thread: | "Exploiting the XmlHttpRequest object in IE" - paper by Amit Kleini: 00020, Amit Klein (AKsecurity) |
| Next by Thread: | Re: "Exploiting the XmlHttpRequest object in IE" - paper by Amit Klein: 00020, Amit Klein (AKsecurity) |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | Mail Home | sitemap | FAQ | advertise |