Top 10 winner
Practical HTTP Header Smuggling
Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
Obfuscating a header name, for example by appending characters after a space, can make a frontend proxy ignore it while the backend still parses it as the real header. The paper gives an error-comparison method for detecting this black-box, and uses it to bypass AWS API Gateway IP restrictions, poison a CloudFront cache with a smuggled Host header, and safely detect CL.CL request smuggling.
Record
- Document
- Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
- Researcher
- Daniel Thatcher
- Published by
- intruder.io
- Topic
- HTTP
In the archive
Related sources
- Request-smuggling confirmation script
- Cache-poisoning confirmation script
- Research extension fork
- Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
Tags
This page is the archive's own catalogue record. The research is the work of Daniel Thatcher, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .