CRLF-Powered Desync Attacks: Beheading HTTP Streams
VulnAbstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
Read full story at PortSwigger Research →