HTTP/2: The Sequel is Always Worse
portswigger.net | research | #black-hat | #web-security | #request-smuggling | #http2 | #desync | #request-tunnelling
Summary
HTTP/2-exclusive desync attacks: implementation flaws and RFC imperfections enable cache poisoning, credential theft and request tunnelling against ALB, WAFs and CDNs, netting multiple max bounties.
- Published
- Collected
Skip to content