Web Hack List

Top 10 winner

From Akamai to F5 to NTLM... with love.

Space-prefixed Content-Length smuggling gadgets pass through Akamai Edge unnormalised and are then cached by the F5 BIG-IP behind it, so repeated requests poison the cache globally. Smuggling an absolute-URL request line redirects a victim site's login portal to an attacker host, capturing authorization tokens and, where Outlook clients auto-discover that host, NTLM credentials.

Record

Researcher
@deadvolvo and d3d
Published by
Malicious Group
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @deadvolvo and d3d, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .