Web Hack List

Collected research

HTTP Response Smuggling

Bugtraq: Whitepaper by Amit Klein: "HTTP Response Smuggling"

Extends HTTP response-splitting attacks by exploiting differences between defensive filters, proxies and browsers. Lone line-ending characters, conflicting Content-Length headers and permissive status-line parsing bypass proposed protections and enable cache poisoning. Worked examples and browser checks explain when these techniques succeed and why blocking only familiar attack strings fails.

Record

Document
Bugtraq: Whitepaper by Amit Klein: "HTTP Response Smuggling"
Researcher
Amit Klein
Published by
seclists.org
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Amit Klein, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .