Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: HTTP REFERER not set in Internet Explorer |
|---|---|
| Date: | Thu, 17 Nov 2005 08:39:36 +0200 |
1.- I don't think that HTTP_REFERER can be used for security purposes. It is totally controlled by the client and an attacker using whatever tool of choice can insert the correct value any time. 2.- The phenomena is due to your use of javascript to invoke navigation. It seems that when javascript is used for navigation in IE, the referer field is left blank (this might be considered by some a security measure against XSS and such) Amichai Shulman CTO Imperva, Inc. 12 Hachilazon St. Ramat-Gan Israel Office: 972-3-6120133 (103) Mobile: 972-54-5885083 E-mail: shulman@imperva.com ................................ InfoWorld product review gives Imperva the HIGHEST SCORE in Application Security http://imperva.com/go/iw/ -----Original Message----- From: Saqib Ali [mailto:docbook.xml@gmail.com] Sent: Wednesday, November 16, 2005 6:17 PM To: webappsec@securityfocus.com Subject: HTTP REFERER not set in Internet Explorer Hello, I am writing a secure application that tracks users on a website by use of HTTP_REFERER. But see like Internet Explorer is not properly populating this field. Visit the following website using IE and Firefox. http://www.xml-dev.com/blog/referer_test.php And click on the Link that says "Click Here" With Firefox, the correct HTTP_REFERER will be displayed after you click the link. But with I.E. the HTTP_REFERER is set to blank. Has anyone ran into this issue? How did you make your application compatible with both I.E and Mozilla based browsers? Because of some security concerns I need the HTTP_REFERER to be set correctly. If it is not possible, I will have to restrict my users to a Mozilla based browser. -- In Peace, Saqib Ali http://www.xml-dev.com/blog/ Consensus is good, but informed dictatorship is better.
| Previous by Date: | Re: HTTP REFERER not set in Internet Explorer, Marc Koschewski |
|---|---|
| Next by Date: | Re: HTTP REFERER not set in Internet Explorer, Amit Klein (AKsecurity) |
| Previous by Thread: | Re: HTTP REFERER not set in Internet Explorer, Oleg Lecinski |
| Next by Thread: | RE: HTTP REFERER not set in Internet Explorer, Jeff Robertson |
| Indexes: | [Date] [Thread] [Top] [All Lists] |