Skip to content
Discussion options

You must be logged in to vote

So question is, is there a way that I can add and arbitrary ascii character or some other technique to bypass this sanitazation ?

I don't think so.
it is necessary to eliminate cr/lf since the presence of cr/lf would allow any header to be inserted in the http request header.

technique to bypass this sanitazation ?

would be a security bug and a big one at that.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@Romulo-Romero
Comment options

@Romulo-Romero
Comment options

Answer selected by Romulo-Romero
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants