Re: NEW ISSUE: Transfer-Encoding in 1.0 messages

* Henrik Nordstrom wrote:
>Who is sending transfer-encoding in HTTP/1.0 messages? Have never seen
>that, and quite outside specifications.
>I have seen transfer-encoding in response to HTTP/1.0 requests however,
>even if that is a MUST NOT..

I do not know any current setup that would cause this, and that browsers
do not agree how to handle this is a good hint that there are none. What
I can easily imagine though is that in ancient times broken servers with
broken proxies would cause this, and that exploits might try to use this
to bypass crude security measures.
Björn Höhrmann · ·
Weinh. Str. 22 · Telefon: +49(0)621/4309674 ·
68309 Mannheim · PGP Pub. KeyID: 0xA4357E78 · 

Received on Friday, 23 November 2007 10:20:23 UTC