[vox] A hypothetical question about the Web's dark underbelly

Karsten M. Self vox@lists.lugod.org
Sat, 17 Jan 2004 02:13:43 -0800


--WYTEVAkct0FjGQmd
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

on Fri, Jan 16, 2004 at 04:08:14PM -0800, Ken Bloom (kabloom@ucdavis.edu) w=
rote:
> On Fri, Jan 16, 2004 at 02:40:23PM -0800, Richard Crawford wrote:

> Routers don't store web pages. Proxies do, but you'll never find
> whether there's a proxy using tracert.=20

Proxies _should_ leave a header message.  Whether this is retrieveable
in the browser client is another issue.

Alternatively, get the user's IP and look for it in your logs.

You can also force-bypass most caching proxies by going https.  Which
you should be doing for authenticated content _anyway_.

Cleartext passwords.  Frames.  Javascript.  Bad.  Bad.  Bad.


Peace.

--=20
Karsten M. Self <kmself@ix.netcom.com>        http://kmself.home.netcom.com/
 What Part of "Gestalt" don't you understand?
  TWikIWeThey: An experiment in collective intelligence.  Stupidity.  Whate=
ver.
    Technical docs, discussion, reviews, opinion.
      http://twiki.iwethey.org/

--WYTEVAkct0FjGQmd
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQFACQrXefG8443k044RAtPzAJ4llYlv3QgmRRzUy/Q9IxfE1NXzgQCfXS3R
2RNk9u5B2LGcb2vHj0fLihQ=
=II1a
-----END PGP SIGNATURE-----

--WYTEVAkct0FjGQmd--