Collected research
Compromising F5 BIGIP with Request Smuggling
Refresh: Compromising F5 BIG-IP With Request Smuggling
F5 BIG-IP fronts its Tomcat TMUI backend with a custom Apache httpd vulnerable to AJP request smuggling: a Transfer-Encoding of chunked, chunked makes httpd drop Content-Length and emit the POST body as a second AJP packet, which Tomcat reads as a fresh request.
Record
- Document
- Refresh: Compromising F5 BIG-IP With Request Smuggling
- Researcher
- Justin Copeland and @praetorianlabs
- Published by
- Praetorian
- Date
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Justin Copeland and @praetorianlabs, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .