Collected research
HTTP Request Smuggling in 2020
Five new request smuggling variants make a proxy and a web server disagree on where a request ends, using header names like Content-Length abcde, a bare CR in a header name, a text/plain body and HTTP/1.2 to slip past the ModSecurity Core Rule Set, yielding cache poisoning against Squid and Abyss. A function-hooking Request Smuggling Firewall is offered as a defence.
Record
- Researcher
- Amit Klein
- Published by
- i.blackhat.com
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Amit Klein, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .