RSSAmplifier

The Fuzzing Project · Sep 20, 2017

How Optionsbleed wasn't found in 2014

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

Shortly after I published details about the Optionsbleed bug I learned about something quite surprising: Others had already discovered this bug before, but have neither pinned it down to Apache nor recognized that it is a security vulnerability. A paper published in 2014 on Arxiv titled "Support for Various HTTP Methods on the Web" mentions servers sending malformed Allow headers. It has examples…

Read on blog.fuzzing-project.org

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.