Web Hack List

Collected research

Bypassing URL Authentication and Authorization with HTTP Verb Tampering

Verb-based access control fails open: rules that list GET and POST permit everything else. A HEAD request reaches the GET handler unauthenticated, and Java EE and PHP also run arbitrary verbs such as JEFF against JSPs, returning the full body. Covers web.xml, ASP.NET authorization and SiteMinder, and gives the deny-all and remove-http-method fixes.

Record

Researcher
Arshan Dabirsiaghi
Published by
Aspect Security
Format
Whitepaper
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Arshan Dabirsiaghi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .