CRLF Injection: How Two Invisible Characters Split an HTTP Response
A carriage return and a line feed are all it takes to inject headers, forge cookies and poison caches. Here is how CRLF injection leads to HTTP response splitting, and how to shut it down.