Ibrahim Ayadhi
Conference
Our team recently attended the RomHack Conference 2025. In keeping with our tradition, we are pleased to share a review of our favorite presentations from the event.
HTTP/1.1 Must Die! The Desync Endgame by James “albinowax” Kettle James Kettle, from PortSwigger, kicked off the day by explaining that the HTTP/1.1 protocol is fundamentally insecure due to its inability to reliably separate requests on a single connection. This leads to desync or “request smuggling” attacks, where an attacker can poison a server’s connection to achieve cache poisoning, session hijacking, and even full-site compromise.