Web Hack List

Later archive addition

NGINX error_page request smuggling

The whitepaper demonstrates that an NGINX `error_page` configuration which redirects to an absolute URL can reinterpret a GET body as a pipelined request. The smuggled request can cross virtual-host boundaries or desynchronize an upstream load balancer; using a named error location is presented as a workaround.

Record

Researcher
Bert JW Regeer and Francisco Oca Gonzalez
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Bert JW Regeer and Francisco Oca Gonzalez, first published at the original source. Preserved copies are kept so the citation survives its host.