TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

HTTP Desync Attacks: Request Smuggling Reborn

75 点作者 karma20将近 6 年前

2 条评论

robocat将近 6 年前
This is incredible and it looks like it could affect massive numbers of sites - unfortunately the article doesn&#x27;t summarise the problem very well.<p>The vector is subtle differences in HTTP header parsing between your front end (reverse proxy, load balancer etc) and your back end (web server).<p>&quot;New Relic deployed a hotfix and diagnosed the root cause as a weakness in an F5 gateway. As far as I&#x27;m aware there&#x27;s no patch available, meaning this is still a zeroday at the time of writing.&quot;.<p>Edit: other major companies he revealed were affected were: PayPal, Trello, Redhat.
评论 #20640639 未加载
评论 #20641061 未加载
Steltek将近 6 年前
I&#x27;ve been waiting to hear more about this since the abstract was published.<p>What was the timelines involved here? PayPal, Trello, and others were contacted over the course of this investigation. It would be nice to know what their response times were to such a serious vulnerability.
评论 #20659657 未加载