Top 10 winner
HTTP Parameter Pollution (HPP)
Minded Security Blog: Http Parameter Pollution a new web attack category (not just a new buzzword :p)
Announces the AppSec EU 2009 talk naming HTTP Parameter Pollution. Injecting query string delimiters lets an attacker add or override parameters a server or client later re-parses, so hardcoded values can be replaced, application behaviour altered and input validation or WAF rules bypassed. Reported against Google Search Appliance scripts, Ask.com and Yahoo Mail Classic.
Record
- Document
- Minded Security Blog: Http Parameter Pollution a new web attack category (not just a new buzzword :p)
- Researcher
- Stefano Di Paola
- Published by
- blog.mindedsecurity.com
- Topic
- HTTP
In the archive
Related sources
- HTTP Parameter Pollution Whitepaper
- HTTP Parameter Pollution Slides
Tags
This page is the archive's own catalogue record. The research is the work of Stefano Di Paola, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .