Web Request Smuggling

HTTP request smuggling (CL.TE/TE.CL/TE.TE/CL.0) — desync front-end and back-end to poison other users' requests. Load behind a proxy/CDN/load-balancer, on "smuggling/desync", or when Content-Length vs Transfer-Encoding handling differs. Signals: front-end + back-end chain, timing anomalies, HTTP/1.1 keep-alive.

NoorQureshi 32e456d 2.2 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-request-smuggling commit 32e456dcec

Frequently asked questions

npx skillmds@latest add noorqureshi/web-request-smuggling