Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CRLF-Powered Desync Attacks: Beheading HTTP Streams

Summary

PortSwigger turns HTTP header injection into a desync worm, with novel methods that shift IP- and connection-locked desyncs into the victim's browser to create XSS and steal HTTPOnly cookies.
Published
Collected

original ↗