|
|
 |
| New User, Welcome! Login |
HTTP Parameter Pollution
| From: |
"Luca carettoni" <luca carettoni ikkisoft com> |
| To: |
bugtraq securityfocus com |
| Cc: |
webappsec lists owasp org, news securiteam com, stefano dipaola wisec it |
| Subject: |
HTTP Parameter Pollution |
| Date: |
Tue - May 19, 2009 05:03 AM |
Hi Folks,
during OWASP AppSec 2009 we have presented a newly discovered input validation vulnerability called "HTTP Parameter Pollution" (HPP).
Basically, it can be defined as the feasibility to override or add HTTP GET/POST parameters by injecting query string delimiters.
During the last months, we have discovered several real world flaws in which HPP can be used to modify the application behaviors, access uncontrollable variables and even bypass input validation checkpoints and WAFs rules. Exploiting such HPP vulnerabilities, we have found several problems in some Google Search Appliance front-end scripts, Ask.com, Yahoo! Mail Classic and many other products.
If you enjoy the web security world, you are kindly invited to have a look at:
http://www.owasp.org/images/b/ba/AppsecEU09_CarettoniDiPaola_v0.8.pdf
We're going to release additional materials in the next future, including a video of the Yahoo! attack vector.
Stay tuned on http://blog.mindedsecurity.com and http://blog.nibblesec.org
Cheers,
Luca Carettoni and Stefano Di Paola
|
|
|
Copyright © 1995-2012 LinuxRocket.net. All rights reserved.
Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!