HTTP header injection
HTTP-päisesüst
olemus
liik veebiründeid, põhineb
HTTP-päiste dünaamilisel genereerimisel
kasutaja sisestatud andmete põhjal
= an attack that uses dynamical creation the HTTP headers based on user input
alaliigid
- HTTP-vastuse lõhestus
- skriptisüst
- ümbersuunamisründed jt
ülevaateid
https://en.wikipedia.org/wiki/HTTP_header_injection
https://www.acunetix.com/blog/web-security-zone/http-header-injection/
http://securityhorror.blogspot.com.ee/2012/03/http-header-injection.html
http://opensourceforu.com/2011/01/securing-apache-part-5-http-message-architecture/
https://isc.sans.edu/forums/diary/HTTP+Headers+the+Achilles+heel+of+many+applications/22382/
https://sites.cs.ucsb.edu/~chris/research/doc/sac18_email.pdf
tõrje
https://studentnet.cs.manchester.ac.uk/resources/library/thesis_abstracts/BkgdReportsMSc11/Hall-Benjamin-bkgd-rept.pdf