HTTP Desync attacks

New research from the PortSwigger team blog to accompany their demonstrations at DEFCON and BlackHat.

This detailed paper introduces their new method of attack, with clear examples and impacts. A very concise description of mitigation options.

Check out the detail here.






