Hacker News new | ask | show | jobs
by buck4roo 1637 days ago
I haven't seen any mentions discussing HTTP request smuggling try. This could cause LP's internal or external load balancers to misdirect requests/responses.

Thoughts on this as a possible root cause?

1 comments

I’ve given this some thought, but I think that this scenario still requires someone to attempt a login with correct credentials. It cannot be the legitimate owner however if the account hasn’t been touched for a year.