writeups.xyz writeups.xyz / Bahruz Jabiyev (@BahruzJabiyev)

Title Vulnerabilities Programs Authors
Gudifu: Guided Differential Fuzzing for HTTP Request Parsing Discrepancies
http: properly reject empty http header field names
FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies
T-Reqs: HTTP Request Smuggling with Differential Fuzzing