473,696 Members | 1,773 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

CERT Advisory CA-2000-02 Malicious HTML Tags Embedded in Client Web Requests



"Alan J. Flavell" <fl*****@ph.gla .ac.uk> wrote:
But the character encoding scheme which is advertised from an HTTP
server via the MIME "charset=" is authoritative, according to RFC2616,
and this attribute should not be omitted according to security alert
CA-2000-02,


Just so everything is in one convenient spot for anyone reading this,
here are some references. The trusecure.com one is rather chilling...

http://honor.trusecure.com/pipermail...ch/008251.html
http://httpd.apache.org/info/css-security/
http://www.cert.org/tech_tips/malici...itigation.html
http://www.cert.org/tech_tips/malicious_code_FAQ.html
http://www.cert.org/advisories/CA-2000-02.html
http://www.cert.org/advisories/CA-1997-20.html

Also see "Re: application/xhtml+xml in IE" thread in
the comp.infosystem s.www.authoring.html nexsgroup.

--
Guy Macon
http://www.guymacon.com/
misc.business.p roduct-dev Moderator

Sep 4 '05 #1
0 1361

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

0
1800
by: Supernews | last post by:
I work for Macromedia and we are looking to form advisory groups to better understand the needs of developers and inform future product development. Those participating will have direct contact with us and other advisory board members and be provided with free Macromedia software. If you are interested in participating, please complete an application found at: http://www.surveymonkey.com/s.asp?u=49439324658. We are looking for developers...
1
2817
by: Lewis Sellers | last post by:
I have a custom JSSESocketFactory class that can take a PKCS12 certificate and password and use it to talk through axis to a secure web service. That works.... The problem is it needs to work on a shared hosting environment where each customer will have thier own certificates, the certificate is used used to verify their identity. I've been staring at the JSSE but am at somewhat of a loss as how to pass the cert location/password TO the...
2
4720
by: Bangalore | last post by:
Hi, Plz, clarify me , with the differences between advisory lock and mandatory locks. Thnanks in advance Bangalore.
6
1616
by: Brett | last post by:
I haven't seen any request for MS Certitified C# developers during my current job search. Is there any value to getting the single cert (as opposed to the four)? I don't have quite as much C# experience and believe the cert may compensate for some of that. Is that a valid reasoning? Thanks, Brett
1
1267
by: Grey | last post by:
i have set up a web application. I want to know that how to integrate it with SSL cert?? If I got the cert already, how can I set the web server in order to be SSL enable web ?? Million Thanks..
7
4949
by: Robert Seacord | last post by:
The CERT/CC has just deployed a new web site dedicated to developing secure coding standards for the C programming language, C++, and eventually other programming language. We have already developed significant content for the C programming language that is available at: https://www.securecoding.cert.org/ by clicking on the "CERT C Programming Language Secure Coding Standard"
0
1200
by: Vadim Grinshpun | last post by:
I'm using a certificate to sign an XML message (encrypted data). When I try to use SignedXML.VerifySignature(cert, false) - it always returns false. It decrypts fine, but the signature verification is a problem. And when I attempt to re-sign the same data with the same cert (which I assume has the same key) on the same computer I get a different didgest value and a
3
1482
by: amanjsingh | last post by:
Hi, I have my website and want to perform this functionality most likely using PHP. Please note that the website is huge and manual editing of pages is not possible. Is there a quick solution tom implement an advisory or an intermediate message like "You are not leaving www.xxxxx. domain and going to external website" when a user clicks on any "external" link on my website? Thanks, AJ
2
2096
by: mubp | last post by:
I am working on ccna cert, will it any beneficial? please advise me for good career in system networking or help desk jobs. thanks
1
1394
by: wenczmastah | last post by:
Hey everyone, I just recently finished a new design for the company am working with, i am still learning webdesign and I would love to get some feedback from fellow web designers the website is : http://www.self-cert-mortgage-centre.co.uk (self cert mortgage company) thanks a lot
0
8666
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main usage, and What is the difference between ONU and Router. Let’s take a closer look ! Part I. Meaning of...
0
9145
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers, it seems that the internal comparison operator "<=>" tries to promote arguments from unsigned to signed. This is as boiled down as I can make it. Here is my compilation command: g++-12 -std=c++20 -Wnarrowing bit_field.cpp Here is the code in...
0
9010
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven tapestry of website design and digital marketing. It's not merely about having a website; it's about crafting an immersive digital experience that captivates audiences and drives business growth. The Art of Business Website Design Your website is...
1
8880
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows Update option using the Control Panel or Settings app; it automatically checks for updates and installs any it finds, whether you like it or not. For most users, this new feature is actually very convenient. If you want to control the update process,...
0
8853
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each protocol has its own unique characteristics and advantages, but as a user who is planning to build a smart home system, I am a bit confused by the choice of these technologies. I'm particularly interested in Zigbee because I've heard it does some...
1
6515
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new presenter, Adolph Dupré who will be discussing some powerful techniques for using class modules. He will explain when you may want to use classes instead of User Defined Types (UDT). For example, to manage the data in unbound forms. Adolph will...
0
5857
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one. At the time of converting from word file to html my equations which are in the word document file was convert into image. Globals.ThisAddIn.Application.ActiveDocument.Select();...
0
4356
by: TSSRALBI | last post by:
Hello I'm a network technician in training and I need your help. I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs. The last exercise I practiced was to create a LAN-to-LAN VPN between two Pfsense firewalls, by using IPSEC protocols. I succeeded, with both firewalls in the same network. But I'm wondering if it's possible to do the same thing, with 2 Pfsense firewalls...
3
1992
bsmnconsultancy
by: bsmnconsultancy | last post by:
In today's digital era, a well-designed website is crucial for businesses looking to succeed. Whether you're a small business owner or a large corporation in Toronto, having a strong online presence can significantly impact your brand's success. BSMN Consultancy, a leader in Website Development in Toronto offers valuable insights into creating effective websites that not only look great but also perform exceptionally well. In this comprehensive...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.