THEMETASEC

Cybersecurity News, Aggregated

CRLF-Powered Desync Attacks: Beheading HTTP Streams

PortSwigger Research · 6 hours ago Vuln

Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power

Read full story at PortSwigger Research →