RSSAmplifier

Egor Homakov · Jan 2, 2014

Path Encoding Vulnerability in https/www redirects.

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

Playing with 302-based header injection (majority of web servers is not vulnerable to it btw) i found one tricky neat bug which can be really useful to leak ?query data by putting them in the #fragment. Remark about the difference : fragment might seem to be more secure than query - no, I don't think so. There are just thousands of open-redirects out there leaking access_token-s . I personally…

Read on homakov.blogspot.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.