Collected research
Bypassing URL Authentication and Authorization with HTTP Verb Tampering
Verb-based access control fails open: rules that list GET and POST permit everything else. A HEAD request reaches the GET handler unauthenticated, and Java EE and PHP also run arbitrary verbs such as JEFF against JSPs, returning the full body. Covers web.xml, ASP.NET authorization and SiteMinder, and gives the deny-all and remove-http-method fixes.
Record
- Researcher
- Arshan Dabirsiaghi
- Published by
- Aspect Security
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Arshan Dabirsiaghi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .