Top 10 winner
From Akamai to F5 to NTLM... with love.
Space-prefixed Content-Length smuggling gadgets pass through Akamai Edge unnormalised and are then cached by the F5 BIG-IP behind it, so repeated requests poison the cache globally. Smuggling an absolute-URL request line redirects a victim site's login portal to an attacker host, capturing authorization tokens and, where Outlook clients auto-discover that host, NTLM credentials.
Record
- Researcher
- @deadvolvo and d3d
- Published by
- Malicious Group
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @deadvolvo and d3d, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .