TE
TechEcho
Home
24h Top
Newest
Best
Ask
Show
Jobs
English
GitHub
Twitter
Home
Password Reset and Web-Cache Poisoning (and a Little Surprise in RFC-2616)
2 points
by
d0bby
about 6 years ago
1 comment
d0bby
about 6 years ago
"How does a deployable web-application know where it is? Creating a trustworthy absolute URI is trickier than it sounds. Developers often resort to the exceedingly untrustworthy HTTP Host header (_SERVER["HTTP_HOST"] in PHP)"...