Web Hack List

Top 10 winner

Exploiting HTTP Parsers Inconsistencies

(Research) Exploiting HTTP Parsers Inconsistencies

A survey of parsing disagreements between proxies and backends. Characters that Node.js, Flask and Spring strip from a request path but Nginx keeps let an attacker slip past location-based ACLs. Header line folding hides a payload from AWS WAF while the backend still reads it as a header value. Paths beginning with @, semicolon or asterisk turn naive URL concatenation in proxy code into SSRF, and header-name bytes that S3 ignores but caches do not allow cache poisoning.

Record

Document
(Research) Exploiting HTTP Parsers Inconsistencies
Researcher
Rafael da Costa Santos
Published by
Rafa's Security Researches
Date
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Rafael da Costa Santos, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .