Web Hack List

Top 10 winner

HTTP Parameter Pollution (HPP)

Announces the AppSec EU 2009 talk naming HTTP Parameter Pollution. Injecting query string delimiters lets an attacker add or override parameters a server or client later re-parses, so hardcoded values can be replaced, application behaviour altered and input validation or WAF rules bypassed. Reported against Google Search Appliance scripts, Ask.com and Yahoo Mail Classic.

Record

Researcher
Stefano Di Paola

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Stefano Di Paola, first published at the original source. Preserved copies are kept so the citation survives its host.