writeups.xyz writeups.xyz / Engin Kirda

Title Vulnerabilities Programs Authors
Gudifu: Guided Differential Fuzzing for HTTP Request Parsing Discrepancies
OAuth 2.0 Redirect URI Validation Falls Short, Literally
http: properly reject empty http header field names
FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies
Web Cache Deception Escalates!
T-Reqs: HTTP Request Smuggling with Differential Fuzzing
You’ve Got (a Reset) Mail: A Security Analysis of Email-Based Password Reset Procedures