10 xena 0 7/21/2025, 12:32:29 PM

Comments (0)

asveikau · 8h ago
I hadn't heard of "http de-sync", so here's an old article by the person cited in this page: https://portswigger.net/research/http-desync-attacks-request...
jasonthorsness · 7h ago
Interesting approach; I always thought the protocol was a bit weird with the way content-length worked vs chunked I understand why they made a whole new version.
beached_whale · 8h ago
HTTP/1.1 will survive a long long time as apps probably don't or won't support HTTP/3 or whatever. They are often proxied though, so there is that.
jrimbault · 8h ago
Nothing to talk about, empty big black scary page.
johnisgood · 8h ago
> HTTP/1.1 is inherently insecure and consistently exposes millions of websites to hostile takeover. On August 6, James Kettle from PortSwigger Research will reveal new classes of desync attack, that enabled him to compromise multiple CDNs and kick off the desync endgame.

> Follow PortSwigger for the full reveal.

With a timer on top.

So yeah, I guess we may know nothing much from them until then.

jrimbault · 8h ago
I meant "empty" of actual information. I'll guess there'll be more on the date. But for now that's just weird and suspect, trying to raise hype for a security related announcement ? weird and suspect
mr_mitm · 8h ago
This is extremely low on details.