SirGod Posted August 18, 2017 Report Posted August 18, 2017 Author: Soroush Dalili Description: This presentation illustrates a number of techniques to smuggle and reshape HTTP requests using features such as HTTP Pipelining that are not normally used by testers. The strange behaviour of web servers with different technologies will be reviewed using HTTP versions 1.1, 1.0, and 0.9 before HTTP v2 becomes too popular! Some of these techniques might come in handy when dealing with a dumb WAF or load balancer that blocks your attacks. Slides: https://www.slideshare.net/SoroushDalili/a-forgotten-http-invisibility-cloak 1 Quote
Nytro Posted August 18, 2017 Report Posted August 18, 2017 Super util, nu e complicat (mai putin partile de encoding si chunked - manual) si poate sa fie extrem de util. Face cineva un plugin de Burp pentru bypass-uri? Quote