3 ms·
Very true, this was likely an attack. Worth noting that mr kettle has done a defcon talk nearly every year on some variant of this attack, the most recent one t
by markasoftware 3mo ago
Very true, this was likely an attack. Worth noting that mr kettle has done a defcon talk nearly every year on some variant of this attack, the most recent one titled "HTTP/1.1 must die" because he rightfully believes that switching to the binary headers of http/2 (specifically in reverse proxy connections to upstream servers) is the only way to systematically prevent these.
- albinowax_ 3mo agoI’ll be back next month with a load of fresh vectors in “Can AI Do Novel Security Research? Meet the HTTP Terminator” https://portswigger.net/research/talks?talkId=36 https://portswigger.net/research/talks?talkId=36 Maybe my last presentation on the topic! Possibly.
- bostik 3mo agoOr as the Risky Business guys crystallise it: "James Kettle breaks the internet. Again."
- pocksuppet 3mo agoWhy the reference to AI? This looks like standard security research.
- albinowax_ 3mo agoIf you follow the link, the presentation abstract should hopefully answer that question! If that doesn’t help I guess you’ll need to wait for the whitepaper to land but I can assure you I didn’t just do my normal research then add AI to the title for clicks :)