Перейти к содержимому

Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond

Black Hat

0:00 / 0:00

Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond

5 383 просмотра · 4 года назад
Black Hat
280 тыс. подписчиков
5 383 просмотра · 4 года назад
Web applications commonly rely on proxy servers adding, modifying, or filtering HTTP headers to pass information to back-end servers. Research in recent years has shown how flawed implementations of these actions can lead to severe security vulnerabilities such as HTTP request smuggling, authentication bypasses, and cache poisoning. Recent request smuggling research has developed new ways to modify headers to abuse these flawed implementations, a technique known as header smuggling. While often overlooked, when explored as its own technique header smuggling can be used to trigger interesting and exploitable behaviours in web applications... By: Daniel Thatcher Full Abstract & Presentation Materials: https://www.blackhat.com/eu-21/briefi...