Top 10 winner
HTTP Smuggling via Higher HTTP Versions
HTTP Request Smuggling via higher HTTP versions
Request smuggling against front ends that terminate HTTP/2 or HTTP/3 and forward HTTP/1.1. Because HTTP/2 header names and values are binary strings that may contain newlines and colons, and content-length and transfer-encoding are not revalidated on downgrade, an attacker can inject a second request into the backend stream. Includes detection methods and a tool.
Record
- Document
- HTTP Request Smuggling via higher HTTP versions
- Researcher
- Emil Lerner
- Published by
- Slideshare
- Date
- Format
- Slides
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Emil Lerner, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .