Chunked-body parsing flaws, making self-XSS great again, using HTTP redirect loops to achieve non-blind SSRFs – ethical hacker news roundup
yeswehack.com | blog | #cloud | #web-security | #ssrf | #roundup | #http-smuggling | #self-xss | #redirect-loop
Summary
Roundup: abusing ambiguous chunk line terminators for HTTP smuggling, 'Make Self-XSS Great Again' via credential-less frames, and using HTTP redirect loops to turn SSRF into full-response reads.
- Published
- Collected
Skip to content