|
|
|
|
|
by lucideer
162 days ago
|
|
Smuggling is a general concern whenever two headers have functionality that interact - it's not specific to prefix masking & given how implementation-based it is, it's not even likely to occur to any arbitrary prefix mask. That's not a reason not to consider it a threat vector when implementing, but no more than when implementing any header (that interacts with another) |
|
You could also solve the problem by standardising the header with the X- prefix, but this is more confusing to users and violates the idea that X- always means "not standardised", at which point the prefix is useless anyway.