Re: History



VK wrote:

> Thomas 'PointedEars' Lahn wrote:
>> VK wrote:
>> > Thomas 'PointedEars' Lahn wrote:
>> >> > 2) If the previus and the current page are in the same security
^^^^^^^^^^^^^^^^^^^^^^^^
>> >> > protocol (http / http or https / https)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>> >> The Same Origin Policy does not apply here.
>> > [...]
>> > It is not Same Origin Policy issue, but security level upgrade /
>> > degrade
>> >
>> > Say if the previous page was _https_://www.server1.com and the current
>> > page is _http_://www.server2.com then you will not be allowed to read
>> > document.referrer (security degrade) Same for vice versa.
>>
>> [...]
>> Your misuse of the term `same security protocol' confused me. HTTP and
>> HTTPS (HTTP over SSL/TLS) are only transfer protocols. The
>> _cryptographic_ or _encryption_ protocol used for the latter is SSL/TLS.
>
> Well, this is a common shortcut to say "secure connection" or "secure
> protocol" about HTTPS,

You wrote "_security_ protocol" which is wrong.

> [windings snipped]


PointedEars
.



Relevant Pages

  • RE: [Full-Disclosure] Apparently the practice was prevalent
    ... > Agreed, but you see, RFC 2616 defines more than just the ... > HTTP protocol. ... It defines the protocol. ... security is the least of your concerns. ...
    (Full-Disclosure)
  • Re: Wrapping TCP communications in HTTP
    ... of course this helps nothing with security:). ... HTTP won't help you a bit since it's not a secure protocol. ... >> communicate between machines. ...
    (microsoft.public.win32.programmer.networks)
  • Re: History
    ... > Thomas 'PointedEars' Lahn wrote: ... >>> 2) If the previus and the current page are in the same security ... >> The Same Origin Policy does not apply here. ... due to the Referer HTTP header sent or not sent by the client, ...
    (comp.lang.javascript)
  • WhiteHat Arsenal 1.06 Beta Released
    ... fitted with an HTTP Response Code lookup utility. ... WHArsenal the best web application security product available. ... WhiteHat Arsenal logs all HTTP Request activities in either XML or HTML ... The Session Manager keeps log files ...
    (SecProg)
  • [NEWS] Cisco Web-Browser Interface Vulnerability
    ... Get your security news from a reliable source. ... Cisco IOS Software Release 12.3JA ... HTTP secure) are not vulnerable. ... http server or ip http secure-server. ...
    (Securiteam)

Loading