
Episode 7: PortSwigger Top 10, TruffleSecurity Drama, and More!
Critical Thinking - Bug Bounty Podcast
00:00
The Role of HCP Headers in HTTP
The Akamai CDN used a technique called 'hop by hop' headers. These are header that aren't stored or used after they're forwarded by a proxy and cache. The process is known as request muggling, where requests concatenated together can lead to bad content being returned back to the user. Jacoba was able to use this trick to get rid of these Header Hopping (HCP) headers in future versions of HTTP. It's been around for 25 years but wasn't widely recognized until now.
Transcript
Play full episode