Skip to content
No results
  • Main Blog
  • Offensive Security
  • Ops and Dev
    • SCOM
    • Web Dev
  • Other
    • SEO
  • About
scomurr.com logo banner

Play for serendipity...

  • Main Blog
  • Offensive Security
  • Ops and Dev
    • SCOM
    • Web Dev
  • Other
    • SEO
  • About
scomurr.com minimal logo

Play for serendipity...

  • Security, Web Attacks

HTTP Request Smuggling–H2 CRLF Header Injection Part 2

In the previous post, we looked at an HTTP/2 downgrade attack where we injected CRLF characters into a header and that allowed us to smuggle the Transfer-Encoding header through the H2 frontend. If the Transfer-Encoding header was provided as a…

  • scomurr
  • 02/20/2023
  • Security, Web Attacks

HTTP Request Smuggling – H2 CRLF Injection

In this next lab, we have to go a bit deeper into the differences between how HTTP and HTTP/2 are transferred over the wire and then ultimately processed by a web application. Once again, we are going to be going…

  • scomurr
  • 01/27/2023
  • Security, Web Attacks

HTTP Request Smuggling – HTTP/2 Downgrade Attack Part 2

In the previous lab we looked at a H2.TE vulnerability. To exploit, we needed to upgrade the request from HTTP to HTTP/2 and rely on the frontend to downgrade back down to HTTP for its communication with the backend system.…

  • scomurr
  • 01/25/2023
  • Security, Web Attacks

HTTP Request Smuggling – HTTP/2 Downgrade Attack

This is a unique attack and takes advantage of an implementation that accepts HTTP/2 requests but then downgrades the requests to HTTP when communicating with the backend systems. The weakness surfaces in how the Transfer-Encoding header is handled by the…

  • scomurr
  • 01/23/2023
  • Security, Web Attacks

HTTP Request Smuggling – Reflected XSS via Headers

In this post, we’re going to be looking at utilizing the headers within a smuggled request to fire a cross site scripting payload. This is the 9th blog post in the series I am publishing dealing with Request Smuggling or…

  • scomurr
  • 01/15/2023
Prev
1 … 4 5 6 7 8 9 10 … 19
Next
  • ssti lab 7 - featured image
    SSTI – Server-side template injection with a custom exploit03/11/2025
  • ssti lab 6 - featured image
    SSTI – Server-side template injection in a sandboxed environment03/04/2025
  • ssti lab 5 featured image
    SSTI – Server-side template injection with information disclosure via user-supplied objects02/25/2025
  • monkey riding a bike - ssti lab 4 - featured image
    SSTI – Server-side template injection in an unknown language with a documented exploit02/20/2025
  • SSTI lab 3 - featured image
    SSTI – Server-side template injection using documentation02/17/2025

Scomurr.com is partially supported by readers like you. When you purchase products or services through our affiliate links, we may receive a commission. This will bring no extra costs to you and helps us to keep on creating content.

Legal

  • Terms and Conditions
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
  • DMCA
  • GDPR
  • Disclaimer

My Favorites

  • VistaSocial
  • NeuronWriter
  • Canva

Socials

Copyright © 2025 - WordPress Theme by CreativeThemes