Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
Godel_unicode
4y ago
0 comments
Save
Share
Among other things, it’s almost certainly the case that the web server isn’t implementing a constant-time string comparison for the URL, which enables you to brute-force the value one character at a time.
0 comments
1 comments · 1 top-level
top
newest
oldest
jesprenj
4y ago
Woah, that sounds interesting, do you have any links to share regarding that issue?
j
/
k
navigate · click thread line to collapse