From: Phrack [security@fooyu.com]
Sent: Thursday, January 23, 2003 8:08 PM
To: jeremiah@whitehatsec.com; bugtraq@securityfocus.com;
webappsec@securityfocus.com; vulnwatch@vulnwatch.org
Subject: Re: TRACE used to increase the dangerous of XSS.
It's really a terrible security hole. Using this method, I have hacked some BBS account of my friends. If you do it properly, it wouldn't be noticed by victim. The following is my code:
Chen haiyan, CISSP
System Security Engineer
HENAN CFONLINE COMMERCE CO., LTD.