Web Hack List

Later archive addition

Using HTTP Pipelining to hide requests

The article uses HTTP/1.1 pipelining to send a benign and a second, different-host request over one TLS connection, concealing the latter’s hostname from observers who cannot decrypt traffic. Testing found the technique worked across AWS CloudFront, while Cloudflare rejected the mismatched Host because it bound requests to the connection’s SNI.

Record

Researcher
Robin Wood - DigiNinja and @digininja

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Robin Wood - DigiNinja and @digininja, first published at the original source. Preserved copies are kept so the citation survives its host.