HTTP/1.1 必须消亡:对 AppSec 领导层的意义
portswigger.net | 博客 | #appsec | #request-smuggling | #http1-must-die | #burp-suite-dast | #enterprise-security | #http2
摘要
面向 AppSec 管理者解读 HTTP/1.1 Must Die 研究:desync 攻击可劫持会话、污染缓存并泄露数据,补丁无法根治协议缺陷,建议用 Burp Suite DAST 排查资产并迁移至上游 HTTP/2。
- 发布时间
- 收录时间
Skip to content