Full Disclosure mailing list archives

Re: Referers Are Evil


From: Tim <tim-security () sentinelchicken org>
Date: Sun, 7 Aug 2005 17:42:35 -0400

What if regular users are behind rotating proxies (e.g., AOL)? :-)

...or on the same network with NAT.

...or on the same network segment with no NAT...  steal cookie, the
proceed to steal the victim's IP with ARP poisoning...

tim
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: