Skip to content

Comment on HTTP/1.1 must die: the desync endgameparent

Comments

Also, this "attack" only works on commercial style complex CDN setups. It wouldn't effect human hosted webservers at all.

All you need is a faulty caching proxy in front of your PHP server. Or maybe that nice anti-bot protection layer.

It really, really is easy to get bitten by this.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.