3 ms·
Hi, I'm the author. This paper is building on techniques explained here: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn https://p
by albinowax_ 5y ago
Hi, I'm the author. This paper is building on techniques explained here: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn https://portswigger.net/research/http-desync-attacks-request...
This attack does not require a MITM - the attacker would use a tool like Burp Suite to issue the (technically RFC-violating) HTTP request. The prefix injection happens because front-end places the attacker's request and the victim's request on the same HTTP/1.1 connection to the back-end, as shown in this diagram: https://portswigger.net/cms/images/9c/c1/4c32-article-http2-desync.png https://portswigger.net/cms/images/9c/c1/4c32-article-http2-...
> isn't the suffix just ignored by the final remote
The back-end treats the suffix as the start of the next request, due to TCP buffering. The vast majority of servers have this kind of accidental pipelining support thanks to TCP.