Web Hack List

Collected research

The Powerful HTTP Request Smuggling

The Powerful HTTP Request Smuggling 💪

HTTP request smuggling on a mobile device management provider's front end let the author inject a redirect into other users' responses. Because MDM clients follow redirects without user interaction, enrolled devices were steered to an attacker-controlled server and made to execute MDM commands, up to a full device wipe.

Record

Document
The Powerful HTTP Request Smuggling 💪
Researcher
Ricardo Iramar dos Santos
Published by
Medium
Date
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ricardo Iramar dos Santos, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .