Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
albinowax_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
albinowax_
5y ago
I think HTTP/2 is fine when it's used end to end. So if you've got a single webserver setup, or a reverse proxy that speaks HTTP/2 to the back-end, it's great. However, if the only way you can use HTTP/2 is by
32.
▲
by
albinowax_
5y ago
Good question! So, my understanding is that the majority of servers that are vulnerable to regular cross-user HTTP Request Smuggling (IE, reuse connections to the back-end server) are exposed to this terrifying response queue poisoning atta
33.
▲
by
albinowax_
5y ago
Yes that's right. If the back-end received a request that didn't contain X-Forwarded-SSL or suchlike, and had a host-header that ended in .netflix.com, it would redirect you to the host-header. I wouldn't exactly class this a
34.
▲
by
albinowax_
5y ago
Hi, I'm the author. This paper is building on techniques explained here: https://portswigger.net/research/http-desync-attacks-request... This attack does not require a MITM - the attacker would use a tool like Bur
35.
▲
by
albinowax_
5y ago
As far as I'm aware, none of the techniques referenced in this paper work on Cloudflare as-is. Of course I probably missed a bunch of variations, so it's still worth them doing some internal checks.
36.
▲
by
albinowax_
5y ago
Hi, I'm the author - please let me know if you have any questions!
37.
▲
by
albinowax_
5y ago
Hi, I'm the author. This paper is about HTTP/2, and the dangerous things that happen behind the scenes with HTTP/1 when people enable it. It's arguing that enabling HTTP/2 on your front-end makes your security worse
38.
▲
Remote code execution in Homebrew by compromising the official Cask repository
(blog.ryotak.me)
4 points
by
albinowax_
5y ago
|
0 comments
39.
▲
Brave browser’s Tor feature found to leak .onion queries to ISPs
(portswigger.net)
2 points
by
albinowax_
6y ago
|
0 comments
40.
▲
by
albinowax_
6y ago
Yep, the original reports are here: https://hackerone.com/reports/488147 https://hackerone.com/reports/510152 And I posted a full whitepaper/presentation on the technique here: https:/&
41.
▲
by
albinowax_
6y ago
HTTP headers are generally treated as ASCII, and Golang's decision to treat them as UTF-8 opens the gate to a range of issues, including the linked unicode normalization attack.
42.
▲
by
albinowax_
6y ago
I think it's worth spelling out that 'chunk thingy' can lead to complete site takeover. For example, using this behaviour I was able to get persistent control of PayPal's login page. That said, I tweeted this rather than
43.
▲
by
albinowax_
6y ago
If you're wondering what kinds of attacks this enables, I think the primary risk is HTTP Request Smuggling https://portswigger.net/research/http-desync-attacks-request... But there's a bunch of hard-to-quanti
44.
▲
by
albinowax_
7y ago
Hi, I work at PortSwigger. > Uber was running some promotional for a free three month license for Burp Proxy This is flat out wrong - the promotional partnership was done with HackerOne. > What's weird about it is that I was usin
45.
▲
Cracking reCAPTCHA, Turbo Intruder Style
(portswigger.net)
1 points
by
albinowax_
7y ago
|
0 comments
46.
▲
by
albinowax_
7y ago
Is moving somewhere that does pair programming a workable option in this situation?
47.
▲
by
albinowax_
7y ago
You can now see the PayPal timelines here: https://hackerone.com/reports/488147 https://hackerone.com/reports/510152 Trello patched it in roughly 10 days. In general I found companies took longer
48.
▲
by
albinowax_
7y ago
I'm suggesting using HTTP/2 between the frontend and backend. I'm saying this is the only reliable fix, not that it's easy to implement. Regarding HTTPS between the frontend and backend, remember that's just HTTP ov
49.
▲
by
albinowax_
7y ago
Glad you like the research! I'll look into emphasising the vector though I'm personally coming to the viewpoint that the root cause is a design flaw in HTTP/1.1, and HTTP/2 is the only truly reliable fix.
50.
▲
by
albinowax_
7y ago
Hi, I'm the author of the article. Regarding point 5, the front-end doesn't need to support pipelining at all, and the back-end doesn't require it either in most cases. Regarding chunk support, yeah you could patch this by di
51.
▲
The age of browser XSS filters is over
(portswigger.net)
3 points
by
albinowax_
7y ago
|
0 comments
52.
▲
by
albinowax_
8y ago
They have a dubious law banning 'dual use' security tools too
53.
▲
Significant new web hacking techniques from 2018
(portswigger.net)
1 points
by
albinowax_
8y ago
|
0 comments
54.
▲
Abusing Meta Programming for Unauthenticated RCE in Jenkins
(blog.orange.tw)
1 points
by
albinowax_
8y ago
|
0 comments
55.
▲
Turbo Intruder: Embracing the Billion-Request Attack
(portswigger.net)
2 points
by
albinowax_
8y ago
|
0 comments
56.
▲
by
albinowax_
8y ago
It's not quite that simple once cookies (and Internet Explorer/Edge) get involved. But it definitely could be secure.
57.
▲
by
albinowax_
8y ago
Bug bounties aren't aimed at malicious actors, or an attempt to outbid the black market. There's a lot of non malicious people out there who are still competent hackers.
58.
▲
by
albinowax_
8y ago
Thanks for the heads up, I'll pass that on.
59.
▲
by
albinowax_
8y ago
Good to hear you like the content. Regarding the title, yeah it's a tricky one to name. Ultimately the top few are new techniques illustrated using vulnerabilities, and all the entries are evaluated through the lens of whether the unde
60.
▲
by
albinowax_
8y ago
If you want to write off the entire post by looking at a single entry, I can see why you'd pick #10 which is the lowest ranked one. It's clearly not as widespread as Tickettrick or as proven as Advanced Flash Vulnerabilities, whic
More ›