[patch] reject http header without colon (:) in the header name

Ben Kallus benjamin.p.kallus.gr at dartmouth.edu
Tue May 7 21:58:34 UTC 2024


Nginx is the only widely-used HTTP server that ignores invalid
field-lines. This behavior makes it trivial to fingerprint.

I never reported this in the past because I assumed Maxim wouldn't
care about that sort of thing. Now that he's out of the picture, maybe
others will see things differently?

-Ben


More information about the nginx-devel mailing list