logo

Three Minutes with the HTTP TRACE Method

ID: 48e5dad3-8d91-5d9d-a76e-a8d4fec254ed

STIX ID: report--48e5dad3-8d91-5d9d-a76e-a8d4fec254ed

Feed Name: Black Hills Infosec Blog

Date Published: 2016-04-04

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post demonstrates that HTTP TRACE responses can expose intermediary-added headers (e.g., X-Forwarded-For), allowing an attacker to spoof those headers and potentially bypass WAF filtering; it explains why Cross-Site Tracing is largely mitigated in modern browsers via CORS and provides an HTML/XHR proof-of-concept to illustrate the technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.