Collected research
FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies
A grammar-based fuzzer for HTTP/2 that mutates frame sequences and frame contents to find anomalies in how CDNs and reverse proxies convert HTTP/2 requests into HTTP/1 for the origin. Testing 12 proxy technologies produced request blackholing, denial of service, query-of-death and request smuggling attacks against the servers behind them.
Record
- Researcher
- Bahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti, Kaan Onarlioglu and Engin Kirda
- Published by
- bahruz.me
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Bahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti, Kaan Onarlioglu and Engin Kirda, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .