Top 10 winner
HTTP Request Splitting vulnerabilities exploitation
nginx configurations that put normalized URI variables into proxy_pass, rewrite or forwarded headers let an attacker inject CRLF and split the request sent to the backend, adding headers, changing method and path, or pipelining a second request; the cases shown leak HttpOnly session cookies, land XSS and reach other backends and buckets.
Record
- Researcher
- Sergey Bobrov
- Published by
- OFFZONE
- Format
- Slides
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Sergey Bobrov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .