3 ms·
You’re right; a bit of a brain fail there for me. Still, doesn’t mitigate attacks against non-HTTP speakers.
by souterrain 6y ago
You’re right; a bit of a brain fail there for me.
Still, doesn’t mitigate attacks against non-HTTP speakers.
- johncolanduoni 6y agoIt does in the sense that you won’t be able to control the websockets payload, so the target server generally won’t respond. The problem here is that the information leak is happening prior to any data being sent over TCP, so the fact that the server will drop the connection as invalid doesn’t help.