473,326 Members | 2,168 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,326 software developers and data experts.

CERT Advisory CA-2000-02 Malicious HTML Tags Embedded in Client Web Requests



"Alan J. Flavell" <fl*****@ph.gla.ac.uk> wrote:
But the character encoding scheme which is advertised from an HTTP
server via the MIME "charset=" is authoritative, according to RFC2616,
and this attribute should not be omitted according to security alert
CA-2000-02,


Just so everything is in one convenient spot for anyone reading this,
here are some references. The trusecure.com one is rather chilling...

http://honor.trusecure.com/pipermail...ch/008251.html
http://httpd.apache.org/info/css-security/
http://www.cert.org/tech_tips/malici...itigation.html
http://www.cert.org/tech_tips/malicious_code_FAQ.html
http://www.cert.org/advisories/CA-2000-02.html
http://www.cert.org/advisories/CA-1997-20.html

Also see "Re: application/xhtml+xml in IE" thread in
the comp.infosystems.www.authoring.html nexsgroup.

--
Guy Macon
http://www.guymacon.com/
misc.business.product-dev Moderator

Sep 4 '05 #1
0 1330

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

0
by: Supernews | last post by:
I work for Macromedia and we are looking to form advisory groups to better understand the needs of developers and inform future product development. Those participating will have direct contact...
1
by: Lewis Sellers | last post by:
I have a custom JSSESocketFactory class that can take a PKCS12 certificate and password and use it to talk through axis to a secure web service. That works.... The problem is it needs to work on...
2
by: Bangalore | last post by:
Hi, Plz, clarify me , with the differences between advisory lock and mandatory locks. Thnanks in advance Bangalore.
6
by: Brett | last post by:
I haven't seen any request for MS Certitified C# developers during my current job search. Is there any value to getting the single cert (as opposed to the four)? I don't have quite as much C#...
1
by: Grey | last post by:
i have set up a web application. I want to know that how to integrate it with SSL cert?? If I got the cert already, how can I set the web server in order to be SSL enable web ?? Million Thanks..
7
by: Robert Seacord | last post by:
The CERT/CC has just deployed a new web site dedicated to developing secure coding standards for the C programming language, C++, and eventually other programming language. We have already...
0
by: Vadim Grinshpun | last post by:
I'm using a certificate to sign an XML message (encrypted data). When I try to use SignedXML.VerifySignature(cert, false) - it always returns false. It decrypts fine, but the signature...
3
by: amanjsingh | last post by:
Hi, I have my website and want to perform this functionality most likely using PHP. Please note that the website is huge and manual editing of pages is not possible. Is there a quick solution...
2
by: mubp | last post by:
I am working on ccna cert, will it any beneficial? please advise me for good career in system networking or help desk jobs. thanks
1
by: wenczmastah | last post by:
Hey everyone, I just recently finished a new design for the company am working with, i am still learning webdesign and I would love to get some feedback from fellow web designers the website is :...
0
by: DolphinDB | last post by:
Tired of spending countless mintues downsampling your data? Look no further! In this article, you’ll learn how to efficiently downsample 6.48 billion high-frequency records to 61 million...
0
by: ryjfgjl | last post by:
ExcelToDatabase: batch import excel into database automatically...
0
isladogs
by: isladogs | last post by:
The next Access Europe meeting will be on Wednesday 6 Mar 2024 starting at 18:00 UK time (6PM UTC) and finishing at about 19:15 (7.15PM). In this month's session, we are pleased to welcome back...
1
isladogs
by: isladogs | last post by:
The next Access Europe meeting will be on Wednesday 6 Mar 2024 starting at 18:00 UK time (6PM UTC) and finishing at about 19:15 (7.15PM). In this month's session, we are pleased to welcome back...
0
by: Vimpel783 | last post by:
Hello! Guys, I found this code on the Internet, but I need to modify it a little. It works well, the problem is this: Data is sent from only one cell, in this case B5, but it is necessary that data...
0
by: jfyes | last post by:
As a hardware engineer, after seeing that CEIWEI recently released a new tool for Modbus RTU Over TCP/UDP filtering and monitoring, I actively went to its official website to take a look. It turned...
1
by: Defcon1945 | last post by:
I'm trying to learn Python using Pycharm but import shutil doesn't work
0
by: Faith0G | last post by:
I am starting a new it consulting business and it's been a while since I setup a new website. Is wordpress still the best web based software for hosting a 5 page website? The webpages will be...
0
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 3 Apr 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome former...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.