View Single Post
  #5 (permalink)  
Old 08-13-2008, 09:36 PM
spikehardin spikehardin is offline
Junior Member
 
Posts: 5
Default

After further review, I noticed that the userAgent (ua) is set by the SOAP client which may explain the blank ua= field. How could the IP address be set to the servers IP address instead of the client's IP address. I am concerned the <targetServer> Proxy Mechanism for authentication requests is a potential vulnerability. Any ideas?
Reply With Quote