← Back to feed
research PortSwigger Research

HTTP/1.1 must die: the desync endgame

PortSwigger Research

Abstract Upstream HTTP/1.1 is inherently insecure and regularly exposes millions of websites to hostile takeover.

Read the full story PortSwigger Research →

Related Coverage

research SAML: A fractal of bad design Trail of Bits · Sep 21 research Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO Kaspersky Securelist · Sep 21 research From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies Unit 42 · Sep 21