WebApp Sec mailing list archives

IE feature to prevent Cross Site Scripting not working?


From: Oh Yong Lee <ohyongle () yahoo com>
Date: 4 Sep 2003 01:51:42 -0000




Hi all,
Microsoft Internet Explorer has this option under Advanced tab: Warn if 
forms submittal is being redirected.

This feature when checked, is supposed to prompt a dialog box if the form 
is posting to a different location from where the form originated from. 
This can prevent Cross Site Scripting from modifying the posting to a form.

However, it does not seem to work. Anybody has any suggestions to this, is 
this a bug? Thanx in advance!


Rdgs
Yong Lee


Current thread: