Top Qs
Timeline
Chat
Perspective
Cross-site tracing
Network security vulnerability exploiting the HTTP TRACE method From Wikipedia, the free encyclopedia
Remove ads
In web security, cross-site tracing (abbreviated "XST") is a network security vulnerability exploiting the HTTP TRACE method.
This article needs additional citations for verification. (July 2007) |
XST scripts exploit ActiveX, Flash, or any other controls that allow executing an HTTP TRACE request. The HTTP TRACE response includes all the HTTP headers including authentication data and HTTP cookie contents, which are then available to the script. In combination with cross domain access flaws in web browsers, the exploit is able to collect the cached credentials of any web site, including those utilizing SSL.
Remove ads
External links
Wikiwand - on
Seamless Wikipedia browsing. On steroids.
Remove ads