HTTP/2: The Sequel is Always Worse - James Kettle (albinowax)

Описание к видео HTTP/2: The Sequel is Always Worse - James Kettle (albinowax)

James Kettle (albinowax) presents his latest research - HTTP/2: The Sequel is Always Worse. This is the director's cut of the presentation that premiered at Black Hat USA on August 5th, 2021. Read the full whitepaper: https://portswigger.net/research

HTTP/2 is easily mistaken for a transport-layer protocol that can be swapped in with zero security implications for the website behind it. Two years ago, James presented HTTP Desync Attacks and kicked off a wave of request smuggling, but HTTP/2 escaped serious analysis. In this presentation, James will take you beyond the frontiers of existing HTTP/2 research, to unearth horrifying implementation flaws and subtle RFC imperfections.

Комментарии

Информация по комментариям в разработке