HTTP Desync Attacks: Request Smuggling Reborn
portswigger.net | research | #bug-bounty | #black-hat | #web-security | #http-desync | #request-smuggling | #portswigger | #paypal
Summary
James Kettle revives HTTP Request Smuggling as HTTP Desync Attacks, splicing requests into victims' connections to poison caches and compromise PayPal's login page, earning over $70k in bounties.
- Published
- Collected
Skip to content