W3C home > Mailing lists > Public > ietf-http-wg@w3.org > October to December 2010

Re: [#95] Multiple Content-Lengths

From: William A. Rowe Jr. <wrowe@rowe-clan.net>
Date: Tue, 12 Oct 2010 21:05:50 -0500
Message-ID: <4CB513FE.4010606@rowe-clan.net>
To: Adrien de Croy <adrien@qbik.com>
CC: Willy Tarreau <w@1wt.eu>, Adam Barth <w3c@adambarth.com>, Julian Reschke <julian.reschke@gmx.de>, "William Chan (?????????)" <willchan@chromium.org>, "Roy T. Fielding" <fielding@gbiv.com>, Mark Nottingham <mnot@mnot.net>, HTTP Working Group <ietf-http-wg@w3.org>
On 10/12/2010 3:47 PM, Adrien de Croy wrote:
> 
> I'm struggling to see how this could be used in an attack though.

Familiarize yourself with the Watchfire HTTP Smuggling attack vector.
http://svn.apache.org/repos/asf/httpd/docs-build/trunk/
Received on Wednesday, 13 October 2010 02:06:32 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Friday, 27 April 2012 06:51:28 GMT