or
or
By clicking below, you agree to our terms of service.
New to HackMD? Sign up
Syntax | Example | Reference | |
---|---|---|---|
# Header | Header | 基本排版 | |
- Unordered List |
|
||
1. Ordered List |
|
||
- [ ] Todo List |
|
||
> Blockquote | Blockquote |
||
**Bold font** | Bold font | ||
*Italics font* | Italics font | ||
~~Strikethrough~~ | |||
19^th^ | 19th | ||
H~2~O | H2O | ||
++Inserted text++ | Inserted text | ||
==Marked text== | Marked text | ||
[link text](https:// "title") | Link | ||
 | Image | ||
`Code` | Code |
在筆記中貼入程式碼 | |
```javascript var i = 0; ``` |
|
||
:smile: | ![]() |
Emoji list | |
{%youtube youtube_id %} | Externals | ||
$L^aT_eX$ | LaTeX | ||
:::info This is a alert area. ::: |
This is a alert area. |
On a scale of 0-10, how likely is it that you would recommend HackMD to your friends, family or business associates?
Please give us some advice and help us improve HackMD.
Do you want to remove this version name and description?
Syncing
xxxxxxxxxx
Browser-Powered Desync Attacks
A New Frontier in HTTP Request Smuggling
Outline
HTTP handling anomalies
Client-side desync
Pause-based desync
Defence & Takeaways
HTTP handling anomalies
Connection state attacks
First-request validation
Connection state attacks
First-request routing
The surprise factor
Detecting connection-locked CL.TE
Detecting connection-locked CL.TE
Detecting connection-locked CL.TE
Detecting connection-locked CL.TE
CL.0 browser-compatible desync
CL.0 browser-compatible desync
H2.0 on amazon.com
H2.0 on amazon.com
Client-side desync
Client-side desync
Client-side desync
Client-side desync
Client-side desync
Client-side desync-case study
Akamai
Akamai - Detect
Akamai - Explore(Stacked HEAD)
Akamai - Attack
Cisco Web VPN
Cisco Web VPN
https://psres.net/launchAttack.html:
Cisco Web VPN
Cisco Web VPN
Verisign
Verisign
Verisign
Pulse Secure VPN
Pulse Secure VPN
Pause-based desync
Pause-based desync - Varnish & Apache
Pause-based desync - ALB
Pause-based desync - ALB
Pause-based desync - Matching timeouts
Pause-based desync - MITM
Pause-based desync - MITM
Pause-based desync
Defence
Takeaways
End
Reference
Source
Slide