Cross-site tracing (XST)

Practice



In web security, cross-site tracing (abbreviated "XST") is a network security vulnerability that exploits the HTTP TRACE method.

XST scenarios use ActiveX , Flash , or any other controls that allow an HTTP TRACE request to be executed. The HTTP TRACE response includes all HTTP headers , including authentication data and the contents of HTTP cookies , which then become accessible to the script. Combined with cross-domain access flaws in web browsers , the exploit can harvest cached credentials from any website, including those that use SSL .

Comments

To leave a comment

If you have any suggestion, idea, thanks or comment, feel free to write. We really value feedback and are glad to hear your opinion.
To reply

Lectures and tutorial on "information security - Cryptography and Cryptanalysis. Steganography. Information protection"

Terms: information security - Cryptography and Cryptanalysis. Steganography. Information protection