Web Hack List

Top 10 winner

Smuggling HTTP headers through reverse proxies

Reverse proxies and back-end frameworks normalize header names differently, so a header Apache unsets as CLIENT_VERIFIED can be resent with a hyphen and still reach Django, Flask or PHP as the same value. Combined with path parsing differentials such as Tomcat's semicolon parameters, this smuggles trusted mTLS headers past the proxy and bypasses authentication.

Record

Researcher
Robin Verton
Published by
Telekom Security
Date
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Robin Verton, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .