Web Hack List

Top 10 winner

Unveiling TE.0 HTTP Request Smuggling: Discovering a Critical Vulnerability in Thousands of Google Cloud Websites

Introduces TE.0 request smuggling, where the front end honours chunked Transfer-Encoding but the back end treats the body as empty, the chunked counterpart of CL.0. Against Google Cloud Load Balancers left on HTTP/1.1, a smuggled prefix redirected live users to an attacker server and captured their session tokens.

Record

Researcher
Paolo Arnolfo and Guillermo Gregorio
Published by
Bugcrowd
Date
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Paolo Arnolfo and Guillermo Gregorio, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .