HTTP/1.1 Must Die: Conquering the 0.CL Challenge
portswigger.net | blog | #appsec | #burp-suite | #web-security | #xss | #http-desync | #request-smuggling | #portswigger | #http-request-smuggling | #0cl | #http | #cl0 | #lab-walkthrough | #james-kettle
Summary
Guest author b3xal dissects 0.CL request smuggling—front-end honors Content-Length: 0 while the back-end does not—and solves PortSwigger's lab with four PoCs using XSS and HEAD techniques.
- Published
- Collected
Skip to content