Web Hack List

Collected research

HTTP Request Smuggling in 2020

Five new request smuggling variants make a proxy and a web server disagree on where a request ends, using header names like Content-Length abcde, a bare CR in a header name, a text/plain body and HTTP/1.2 to slip past the ModSecurity Core Rule Set, yielding cache poisoning against Squid and Abyss. A function-hooking Request Smuggling Firewall is offered as a defence.

Record

Researcher
Amit Klein
Published by
i.blackhat.com
Format
Whitepaper
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Amit Klein, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .