Current versions of Internet Explorer do not include a Referer header
when following off-site links contained in a page that was accessed over
HTTPS. In this situation, Firefox includes the Referer header provided that the
off-site link is also being accessed over HTTPS, even if it belongs to a different
domain. Hence, sensitive data placed into URLs is vulnerable to leakage in
Referer logs even where SSL is being used.
Figure 7-4: When session tokens appear in URLs, these will be transmitted
in the Referer header when users follow an off-site link or their browser
loads an off-site resource.
Do'stlaringiz bilan baham: |