The curl quirk that exposed Burp Suite & Google Chrome
portswigger.net | research | #burp-suite | #vulnerability-research | #web-security | #curl | #local-file-disclosure | #google-chrome
Summary
How curl's @-prefixed --data-binary turns data into a file read: the quirk let malicious requests exfiltrate local files through 'copy as curl' in Burp Suite Pro, and also affected Google Chrome.
- Published
- Collected
Skip to content