Get a Pentest and security assessment of your IT network.

News

Header injection in Sinatra/Rack

Rack is the root of the problem. Chrome uses n internally as a delimiter for “arrays of cookies” so it blocks n-based injections, but r-based are working fine. This means all web ruby software relying on Rack headers validation is vulnerable to header injection. Even Rails, they have “monkey patch” removing rn from “Location” header, but the rest of headers stay untouched. When browser sees non-empty Location it ignores all other headers but Set-Cookie.”]

Source: http://homakov.blogspot.com/2014/01/header-injection-in-sinatra.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Tracking wearable devices could be very easy via Bluetooth Low Energy

News

Social Networks Part 1 Who exactly are you disclosing your life story to?