Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

HTTP/1.1 Must Die: Conquering the 0.CL Challenge

Summary

Guest author b3xal dissects 0.CL request smuggling—front-end honors Content-Length: 0 while the back-end does not—and solves PortSwigger's lab with four PoCs using XSS and HEAD techniques.
Published
Collected

original ↗

Related coverage

back