Collected research
Response Smuggling- Pwning HTTP-1.1 Connections
Instead of desynchronising requests, the attacker desynchronises the response queue: smuggled requests leave orphan responses that can be claimed to steal another user's response and session cookies. A smuggled HEAD request makes a proxy misjudge body length, concatenating or splitting later responses so headers become HTML body.
Record
- Researcher
- Martin Doyhenard
- Published by
- media.defcon.org
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Related sources
- #HITBCW2021 D2 - Response Smuggling: Pwning HTTP/1.1 Connections - Martin Doyhenard
- Response Smuggling: Exploiting HTTP/1.1 Connections ▪ Martin Doyhenard ▪ Ekoparty 2021
- DEF CON 29 - Martin Doyhenard - Response Smuggling: Pwning HTTP 1 1 Connections
Tags
This page is the archive's own catalogue record. The research is the work of Martin Doyhenard, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .