Newsy / PortSwigger
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
Wydawca udostępnia w kanale tylko zajawkę. Pełny tekst przeczytasz u źródła.