Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Julian Oliver
Julian Oliver
@JulianOliver@mastodon.social  ·  activity timestamp 2 weeks ago

A reminder that with the current trunk (and a few recent point releases) of Nginx, HTTP/2 can finally be set on the backend, mitigating for HTTP request 'smuggling' attacks through the rev proxy.

https://portswigger.net/web-security/request-smuggling

#infosec #sysadmin

What is HTTP request smuggling? Tutorial & Examples | Web Security Academy

In this section, we'll explain HTTP request smuggling attacks and describe how common request smuggling vulnerabilities can arise. Labs If you're already ...
  • Copy link
  • Flag this post
  • Block
Tom
Tom
@pertho@mastodon.bsd.cafe  ·  activity timestamp 2 weeks ago

@JulianOliver

proxy_http_version 2;

Should do it, right? 👍

  • Copy link
  • Flag this comment
  • Block
Julian Oliver
Julian Oliver
@JulianOliver@mastodon.social  ·  activity timestamp 2 weeks ago

@pertho That's it!

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct