3 ms·
This attack is on HTTP compression, which covers only the body of the request, not the headers [1]. 1. http://en.wikipedia.org/wiki/Http_compression http://en.
by AnIrishDuck 13y ago
This attack is on HTTP compression, which covers only the body of the request, not the headers [1].
1. http://en.wikipedia.org/wiki/Http_compression http://en.wikipedia.org/wiki/Http_compression
- StavrosK 13y agoYeah, so you'll have to be able to write to, but not read, the body of the request, observe the ciphertext on the wire and guess things in the body only. So this is only good for CSRF tokens and the like, and only if you can write to the plaintext you want to guess but not just outright read it.