TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

HTTP Desync Attacks: Request Smuggling Reborn

75 pointsby karma20almost 6 years ago

2 comments

robocatalmost 6 years ago
This is incredible and it looks like it could affect massive numbers of sites - unfortunately the article doesn&#x27;t summarise the problem very well.<p>The vector is subtle differences in HTTP header parsing between your front end (reverse proxy, load balancer etc) and your back end (web server).<p>&quot;New Relic deployed a hotfix and diagnosed the root cause as a weakness in an F5 gateway. As far as I&#x27;m aware there&#x27;s no patch available, meaning this is still a zeroday at the time of writing.&quot;.<p>Edit: other major companies he revealed were affected were: PayPal, Trello, Redhat.
评论 #20640639 未加载
评论 #20641061 未加载
Steltekalmost 6 years ago
I&#x27;ve been waiting to hear more about this since the abstract was published.<p>What was the timelines involved here? PayPal, Trello, and others were contacted over the course of this investigation. It would be nice to know what their response times were to such a serious vulnerability.
评论 #20659657 未加载