Web Hack List

Collected research

FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies

A grammar-based fuzzer for HTTP/2 that mutates frame sequences and frame contents to find anomalies in how CDNs and reverse proxies convert HTTP/2 requests into HTTP/1 for the origin. Testing 12 proxy technologies produced request blackholing, denial of service, query-of-death and request smuggling attacks against the servers behind them.

Record

Researcher
Bahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti, Kaan Onarlioglu and Engin Kirda
Published by
bahruz.me
Format
Whitepaper
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Bahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti, Kaan Onarlioglu and Engin Kirda, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .