Hacker News new | past | comments | ask | show | jobs | submit login

This is both fantastic discussion of the ability to quickly check for vulnerabilities in ways never possible at scale before and also discussion of a little-known vulnerability that even the security experts were not aware of. The security guys at Imperva Incapsula just wrote up how they protect their system against this here (https://www.incapsula.com/blog/http-host-header-fix.html) – and in their tests, the only vulnerability they found was their own tests. But they wouldn’t have done it until the BlackHat presentation.



Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: