Hacker Newsnew | past | comments | ask | show | jobs | submitlogin



http.sys lives at the bottom of HTTP processing/consumption stack, and that's where vulnerability is. HttpListener simply uses Windows HTTP stack's services, as IIS and others do.


It looks like HttpListener doesn't support kernel caching at all which means it's not vulnerable to this attack.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: