The curl quirk that exposed Burp Suite and Google Chrome(portswigger.net) |
The curl quirk that exposed Burp Suite and Google Chrome(portswigger.net) |
This technique is likely to work on anything with 'copy as curl' functionality, and may also work on some websites with SSRF where you control a request body or header name.
I wrote this up but full credit goes to Paul Mutton for reporting it to our bug bounty program, and agreeing to let us publish the technique.