Web Hack List

Collected research

Response Smuggling- Pwning HTTP-1.1 Connections

Instead of desynchronising requests, the attacker desynchronises the response queue: smuggled requests leave orphan responses that can be claimed to steal another user's response and session cookies. A smuggled HEAD request makes a proxy misjudge body length, concatenating or splitting later responses so headers become HTML body.

Record

Researcher
Martin Doyhenard
Published by
media.defcon.org
Format
Whitepaper
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Martin Doyhenard, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .