Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have introduced a new category of HTTP request smuggling attacks known as >>CRLF-Powered Desync Attacks.<< This method exploits a frequently overlooked HTTP header injection vulnerability, which can lead to full account takeovers, theft of HTTPOnly cookies, and even the creation of self-propagating desync worms. […] The post New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/new-crlf-desync-attack/
![]()

