Three Minutes with the HTTP TRACE Method
ID: 48e5dad3-8d91-5d9d-a76e-a8d4fec254ed
STIX ID: report--48e5dad3-8d91-5d9d-a76e-a8d4fec254ed
Feed Name: Black Hills Infosec Blog
This blog post demonstrates that HTTP TRACE responses can expose intermediary-added headers (e.g., X-Forwarded-For), allowing an attacker to spoof those headers and potentially bypass WAF filtering; it explains why Cross-Site Tracing is largely mitigated in modern browsers via CORS and provides an HTML/XHR proof-of-concept to illustrate the technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
