Web Hack List

Collected research

Trailing Danger: exploring HTTP Trailer parsing discrepancies

Audits around 70 HTTP implementations for how they handle chunked trailer fields and shows that merging trailers into the header section, or validating them loosely, lets an attacker inject headers the front-end never inspected. That bypasses proxy access rules and vhost checks, and where the framing headers can be overridden it splits one request into two.

Record

Researcher
Sebastiano Sartor, Sebastiano Sartor - sebsrt and @s3bsrt
Published by
sebsrt - Sebastiano Sartor
Date
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Sebastiano Sartor, Sebastiano Sartor - sebsrt and @s3bsrt, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .