
Preventing Malicious Request Loops
1/21/2016
This post details the 'Via' header mechanism for preventing HTTP request loops, explains how Cloudflare implements it, and highlights the vulnerability introduced by non-compliant proxy services that strip or modify these headers. It calls for industry-wide adoption of RFC 7230 compliance to prevent these attacks.