"Web servers that respond to the OPTIONS HTTP method expose what other methods are supported by the web server, allowing attackers to narrow and intensify their efforts."
Which feels like a bit of a stretch, it's only a problem if it enables other attacks and given the the number of HTTP methods it won't slow down any attacker.
It's a bit like saying "a login form exposes where to input user password for a brute-force attack" ;)
Vincent Pek
unread,
Oct 30, 2020, 5:45:48 AM10/30/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Prometheus Users
agree on that.. but my company policy states that even for info/low I need to seek waiver to close it off..
just need some closure on this. if it is indeed used then i can declare that it is required and accept it.
l.mi...@gmail.com
unread,
Oct 30, 2020, 6:15:18 AM10/30/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
So I would just say that it's part of the standard for communicating between browser and the server. But I'm no expert on web security so don't quote me on that.
Harald Koch
unread,
Oct 30, 2020, 9:26:09 AM10/30/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Prometheus Users
On Fri, Oct 30, 2020, at 05:45, Vincent Pek wrote:
agree on that.. but my company policy states that even for info/low I need to seek waiver to close it off..
So ... seek a waiver? Or better - get your security team to disable this particular check, since it's both useless (attackers can just probe HTTP methods without asking first) and wrong (RESTful APIs and CORS both use the OPTIONS method).
--
Harald
Vincent Pek
unread,
Nov 4, 2020, 5:17:11 AM11/4/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Prometheus Users
to seek a waiver I will need some proof that options is indeed required to be used or some form of declaration from the devs.