HTTP desync attacks: request smuggling reborn
portswigger.net·14h·
Discuss: Hacker News
Flag this post

James Kettle

**Published: **07 August 2019 at 21:00 UTC

**Updated: **03 September 2025 at 07:37 UTC

Abstract

HTTP requests are traditionally viewed as isolated, standalone entities. In this paper, I’ll explore forgotten techniques for remote, unauthenticated attackers to smash through this isolation and splice their requests into others, through which I was able to play puppeteer with the web infrastructure of numerous commercial and military systems, rain exploits on their visitors, and harvest over $70k in bug bounties.

Using these targets as case studies, I’ll show you how to delicately amend…

Similar Posts

Loading similar posts...