Re: [PATCH] Truncate HTTP response bodies to match clen

From: Henrik Nordstrom <henrik_at_henriknordstrom.net>
Date: Sun, 28 Jun 2009 21:46:14 +0200

fre 2009-06-26 klockan 12:05 -0600 skrev Alex Rousskov:

> TODO: simply truncating read content would not work for pipelined
> responses. We should preserve extra content for the next transaction on
> a pconn.

Correct, and is a major reason NOT to do pipelining as it then becomes
impossible to protect from the response splitting attack you just
closed...

Regards
Henrik
Received on Sun Jun 28 2009 - 19:46:28 MDT

This archive was generated by hypermail 2.2.0 : Mon Jun 29 2009 - 12:00:06 MDT