2007/07/13

Apache Block TRACE/TRACK XSS

Secure Apache TRACE Vulnerabilities

Set follows in Apache configuration

# Block TRACE/TRACK XSS vector
RewriteEngine On
RewriteCond %{REQUEST_METHOD} ^TRAC(E|K)
RewriteRule .* - [F]

No comments:

Post a Comment