Collected research
HTTP Response Smuggling
Bugtraq: Whitepaper by Amit Klein: "HTTP Response Smuggling"
Extends HTTP response-splitting attacks by exploiting differences between defensive filters, proxies and browsers. Lone line-ending characters, conflicting Content-Length headers and permissive status-line parsing bypass proposed protections and enable cache poisoning. Worked examples and browser checks explain when these techniques succeed and why blocking only familiar attack strings fails.
Record
- Document
- Bugtraq: Whitepaper by Amit Klein: "HTTP Response Smuggling"
- Researcher
- Amit Klein
- Published by
- seclists.org
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Amit Klein, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .