Don't like this style? Click here to change it! blue.css

LOGIN:
Welcome .... Click here to logout

Request Smuggling

OK so popular demand was to teach some request smuggling which is a cool concept.

It's a little tough to setup the vulnerable site for this, so I'm leaning on the PortSwigger labs (which were some of the first popularizers of this vuln).

I think this might be us walking through someone else's nice content but here's my TLDR:

There is a whole realm of web exploit where tweaking your HTTP headers can trigger unusual/insecure behavior in the servers you are targeting.

This class of attacks is at the intersection of network security and server configurations.

Here's an image from the PortSwigger blogs that captures the essence. I'll pivot over to their content now:

Details:

Let's pivot to their notes

Now let's do a lab or two.