A security auditor is reviewing a web application's configuration. They discover that the application allows HTTP TRACE requests, and sensitive information, such as HTTPOnly cookies and authentication headers, is reflected back in the TRACE response. Which of the following attack types is facilitated by this misconfiguration?
- AXML External Entity (XXE) Injection
- BServer-Side Request Forgery (SSRF)
- CCross-Site Tracing (XST)
- DHTTP Parameter Pollution (HPP)
Show answer & explanationAnswer & explanation
Correct answer: C. Cross-Site Tracing (XST)
Cross-Site Tracing (XST) exploits the HTTP TRACE method. If a web server allows TRACE requests and reflects sensitive information in the response, an attacker can use XSS (if also present) to make a browser send a TRACE request to the vulnerable server and then read the sensitive information (like HTTPOnly cookies, which are otherwise inaccessible to JavaScript).
Why the other options are wrong
- A. XXE Injection involves exploiting XML parsers to read local files or make network requests.
- B. SSRF makes the server issue requests on behalf of the attacker to internal or external resources.
- D. HPP involves manipulating parameters in HTTP requests to bypass security logic, unrelated to TRACE.
Cross-Site Tracing (XST)
An attack that exploits the HTTP TRACE method. If a web server allows TRACE requests and reflects client-supplied information (including HTTPOnly cookies) in the response, an attacker can use Cross-Site Scripting (XSS) to initiate a TRACE request and retrieve sensitive information that would otherwise be inaccessible to JavaScript.
- Exploits HTTP TRACE method.
- Requires TRACE to be enabled on the server.
- Often combined with XSS to read HTTPOnly cookies.
- Mitigated by disabling TRACE method.
Memory trick: TRACE leaks secrets, XST completes the feats.