Search:     Advanced search
server monitoring

HTTP TRACE / TRACK Methods

Article ID: 11213
Last updated: 27 Jan, 2009
Views: 1952
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

HTTP TRACE / TRACK Methods

This script is Copyright (C) 2003 E-Soft Inc.

FamilyWeb Servers
Plugin ID11213
Bugtraq ID9506
9561
11604
CVE IDCVE-2004-2320

Description:
Synopsis :

Debugging functions are enabled on the remote web server.

Description :

The remote webserver supports the TRACE and/or TRACK methods. TRACE
and TRACK are HTTP methods which are used to debug web server
connections.

In addition, it has been shown that servers supporting the TRACE
method are subject to cross-site scripting attacks, dubbed XST for
"Cross-Site Tracing", when used in conjunction with various weaknesses
in browsers. An attacker may use this flaw to trick your legitimate
web users to give him their credentials.

See also :

http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.apacheweek.com/issues/03-01-24
http://www.kb.cert.org/vuls/id/867593

Solution :

Disable these methods.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
This article was:   Helpful | Not Helpful
Prev   Next
Apache HTTP Server mod_access IP Address Netmask Rule Bypass     No 404 check