Re: attn. buzzy...red x....first draft....



On Thu, 27 Oct 2005 18:06:59 +0100, "TD" <tdefries@xxxxxxxxxxx> wrote:


>Some firewall admins

Speaking as someone who has secured networks large and small for over a
decade now, here is my 2d's worth.

>don't want the initial HTTP GET operation to send the
>user's operating system,

That's implied from the user agent header, to strip this *will* cause
interoperability problems.

> browser type,

Sites can and do depend on this for proper functionality.

>client e-mail address,

I don't know of any client request header which encodes the clients email
address.

> referring URL,

By all means strip referrers from 3rd party sites, but stripping 1st party
http referrers is an act of silliness.

>and in some cases, intermediate proxy addresses,

Stripping RFC addressed proxy headers & the forwarded for header is
acceptable.


>to the webserver in
>question, because they don't want to leak potentially sensitive data. So
>they will enable something like 'remove client connection info' or 'protect
>privacy' to mask some of it.

Blocking 1st party http referrers does not protect privacy in any way shape
or form.

'firewall' software which strips them blindly is exceedingly broken snake
oil.


>It appears that your site, unlike every other site I can recall accessing,
>won't display images without receiving all that initial HTTP GET info.

It's a very common mechanism to prevent bandwidth theft.


greg



--
"Access to a waiting list is not access to health care"
.



Relevant Pages

  • Re: Cant send back null class reference as SOAP Header?
    ... State is maintained on the server (no ... the client actually maintains the key to the state ... If they then retry the request, the flag won't be sent, will it? ... The header is defined as Direction.InOut on every ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: Will the real Tulio Prego please stand up
    ... "This line is added to the header of a posted article by the server. ... qualified domain name of the client host posting the article. ... your ISP, and it never reaches the internet at-large. ...
    (rec.music.makers.squeezebox)
  • Re: Help with DLLs & CALLBACKS
    ... The client program would not be in the DLL's header. ... DLL if you didn't have the function prototype for the functions to call? ... callback on every call, so making it a static extern variable makes no sense. ...
    (microsoft.public.vc.mfc)
  • Re: Accessing Authenticate Header
    ... .NET HTTPModule receives request from client on the BeginRequest event, ... HTTP_AUTHORIZATION header is not included on the HTTPRequest because IIS ... > 1) IIS configuration for anonymous access ONLY (NO Basic Authentication) ... > 3) Handler or Module reads the AUTHORIZATION header and authenticates ...
    (microsoft.public.dotnet.security)
  • Re: GroupWise 7.0.1-Client: Disposition-Notification-To?
    ... Teilen auch Server, vor allem beim Senden, denn da legt der *Client* ... selber ganz alleine die Header fest, und versendet selber per SMTP. ...
    (de.comp.sys.novell)