Collected research
The Single-Packet Shovel: Digging for Desync-Powered Request Tunnelling
HTTP/2 to HTTP/1.1 downgrade request tunnelling is widely dismissed as a smuggling false positive; sending a deliberately invalid tunnelled request exposes it, and firing a group of requests as a single packet turns a roughly one-in-two-thousand race into a hit about eighty percent of the time. Because the tunnelled request rides inside the body, front-end access rules and WAF checks do not apply.
Record
- Researcher
- Thomas Stacey and @AssuredAB
- Published by
- Assured AB
- Topic
- HTTP
In the archive
Related sources
- Research scanner template
- Single-Packet Shovel tools and resources
- The Single-Packet Shovel: Digging For Desync-Powered Request Tunnelling - Thomas Stacey
Tags
This page is the archive's own catalogue record. The research is the work of Thomas Stacey and @AssuredAB, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .