cross-site tracing
trasseerimisrünne
olemus
veebirünne autentimisandmete ja
muu konfidentsiaalse teabe hankimiseks,
põhineb skriptisüstil ja
HTTP-meetodil TRACE või TRACK
=
attack involving the use of cross-site scripting and the TRACE or TRACK HTTP methods
ülevaateid
https://en.wikipedia.org/wiki/Cross-site_tracing
https://owasp.org/www-community/attacks/Cross_Site_Tracing
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
https://capec.mitre.org/data/definitions/107.html
https://www.youtube.com/watch?v=FSBxzXjOUTA
https://deadliestwebattacks.com/2010/05/18/cross-site-tracing-xst-the-misunderstood-vulnerability/
https://odsc.medium.com/how-is-cross-site-scripting-different-from-other-related-attacks-bcfd08e3e056
tõrje
https://zenconix.com/cross-site-tracing-and-its-prevention-xst/
http://opensourceforu.com/2010/12/securing-apache-part-4-xst-xshm/
https://www.imyfone.com/change-location/prevent-cross-site-tracking/