Penetration Testing mailing list archives

RE: http TRACE option


From: <benoni.martin () accenture com>
Date: Mon, 21 Jan 2008 16:04:14 +0100

This should give you an idea:
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf.

B.

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of pentestr
Sent: jeudi 17 janvier 2008 21:41
To: Pentest Mailinglist
Subject: http TRACE option

Hi,
what is the issue if TRACE option is enabled in web servers ? Nessus 
results always display it as warning.
any idea...

Thanks in advance.
Rgds.
P.T.

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------




This message is for the designated recipient only and may contain privileged, proprietary, or otherwise private 
information.  If you have received it in error, please notify the sender immediately and delete the original.  Any 
other use of the email by you is prohibited.

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: