Collected research
XXE-scape through the front door: circumventing the firewall with HTTP request smuggling
Behind a firewall that blocked outbound HTTP, the researcher used local-DTD XXE tricks to exfiltrate internal data over DNS, then chained the XXE with an HTTP request smuggling desync on a whitelisted host. Smuggling let an attacker store and later read the internal responses (for example http://127.0.0.1/api/secret) in their own profile, escalating a low-impact bug into sensitive data disclosure.
Record
- Published by
- honoki.net
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of honoki.net, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .