Re: How can I analog this bug to my colleague

2014-08-22 Thread Mark Thomas
On 22/08/2014 03:31, ?? wrote: I read an article on the internet that says that Tomcat was found to accept content-length headers with chunked encoding over any HTTP connector and multiple content-length headers in a request when using the AJP connector. This could allow attackers

How can I analog this bug to my colleague

2014-08-21 Thread ??????
I read an article on the internet that says that Tomcat was found to accept content-length headers with chunked encoding over any HTTP connector and multiple content-length headers in a request when using the AJP connector. This could allow attackers to poison a web-cache, bypass web

How can I analog this bug to my colleague

2014-08-21 Thread ??????
I read an article on the internet that says that Tomcat was found to accept content-length headers with chunked encoding over any HTTP connector and multiple content-length headers in a request when using the AJP connector. This could allow attackers to poison a web-cache, bypass web