[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [WEB SECURITY] Bypassing URL Authentication and Authorization with HTTP Verb Tampering



> Not sure how you can question whether or not I know the RFC

I'm not questioning your familiarity with the RFC, I'm questioning your
assertion that "The HEAD-redirect-to-GET and arbitrary verbs being
forwarded to GET handler are the unique takeaways".

A web server working as per the RFC is a unique discovery worthy of a
paper in what way?

Martin...


----------------------------------------------------------------------------
Join us on IRC: irc.freenode.net #webappsec

Have a question? Search The Web Security Mailing List Archives:
http://www.webappsec.org/lists/websecurity/

Subscribe via RSS:
http://www.webappsec.org/rss/websecurity.rss [RSS Feed]

Join WASC on LinkedIn
http://www.linkedin.com/e/gis/83336/4B20E4374DBA



Brought to you by http://www.webappsec.org
Search this site