タグ

ブックマーク / httpoxy.org (1)

  • httpoxy

    Recommended reading Summary What Is Affected Immediate Mitigation Prevention Interesting, but once you’ve mitigated How It Works Why It Happened History of httpoxy CVEs A CGI application vulnerability (in 2016) for PHP, Go, Python and others httpoxy is a set of vulnerabilities that affect application code running in CGI, or CGI-like environments. It comes down to a simple namespace conflict: RFC 3

    rryu
    rryu 2016/07/19
    HTTP_PROXYという環境変数名はアレだから使うのをやめようみたいな話が昔あったような気がする。
  • 1