Web Hack List

Other nomination

HTTP Request Smuggling in 2020

Five new request smuggling variants make a proxy and a web server disagree on where a request ends, using header names like Content-Length abcde, a bare CR in a header name, a text/plain body and HTTP/1.2 to slip past the ModSecurity Core Rule Set, yielding cache poisoning against Squid and Abyss. A function-hooking Request Smuggling Firewall is offered as a defence.

Record

Researcher
Amit Klein
Format
Whitepaper

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Amit Klein, first published at the original source. Preserved copies are kept so the citation survives its host.