Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Beware the false false-positive: how to distinguish HTTP pipelining from request smuggling

Summary

Kettle explains how to distinguish HTTP pipelining false positives from real request smuggling, covering connection-locked smuggling, connection state attacks and client-side desync.
Published
Collected

original ↗

Related coverage

back