3 ms·
>This particular text isn't a vulnerability (after all, HTTP is full of known plaintext). This isn't quite a proof. You'd need to show that HTTP is not vulnera
by jsprogrammer 11y ago
>This particular text isn't a vulnerability (after all, HTTP is full of known plaintext).
This isn't quite a proof. You'd need to show that HTTP is not vulnerable to such an attack.
I don't think HTTP requires a starting block.
HTTP2 apparently requires a client's first message to be/start with:
0x505249202a20485454502f322e300d0a0d0a534d0d0a0d0a
I'd guess that is much longer than any block that HTTP mandates.
Maybe I am reading things wrong?
- danielhlockard 11y agodoesn't HTTP require "VERB URL HTTP/VERSION" ?
- jsprogrammer 11y agoYes, but there are many VERBs and URLs.
- danielhlockard 11y agobut "GET / HTTP/1.1" is likely the most common.
- jsprogrammer 11y agoI'd believe it might be the most common (though, I'd guess "GET /favicon.ico HTTP/1.1" to be a real contender). I highly doubt either are anywhere more than a small fraction of the total HTTP requests though.
- arcatek 11y agoNot actually requiring something to start with a fixed string doesn't really mean anything when every message begins with a fixed string because it's just the way to do.