Skip to content
  • Home
  • LinkedIn
  • Contact
scomurr.com
  • Home
  • LinkedIn
  • Contact
scomurr logo

  • Security, Web Attacks

HTTP Request Smuggling – HTTP/2 Request Tunnelling

Time for another one of the advanced labs on the PortSwigger Web Security Academy. For this lab, we are dealing with an HTTP/2 downgrade attack that allows the attacker to smuggle a request to the backend. Due to how the…

  • scomurr
  • 03/19/2023
  • Security, Web Attacks

HTTP Request Smuggling – Web Cache Poisoning for Deception

This lab is a bit similar to the last, however, it has a completely different purpose. In the previous, we poisoned the cache in an attempt to trigger an XSS. In this lab, we are looking at poisoning a cache…

  • scomurr
  • 03/12/2023
  • Security, Web Attacks

HTTP Request Smuggling – Web Cache Poisoning

This lab is a lot of fun and requires chaining together techniques to fully exploit. First, we have to identify if, where, and how the application is vulnerable to a smuggling attack. Once that has been established, we need to…

  • scomurr
  • 03/05/2023
  • Security, Web Attacks

HTTP Request Smuggling – Admin Access via CL.0 Vulnerability

This next lab represents an interesting vulnerability where specific paths/routes within an application are vulnerable to desync when there is no expectation of anything other than the intended HTTP verb ever showing as part of a request. These are very…

  • scomurr
  • 02/25/2023
  • Security, Web Attacks

HTTP Request Smuggling–H2 CRLF Header Injection Part 2

In the previous post, we looked at an HTTP/2 downgrade attack where we injected CRLF characters into a header and that allowed us to smuggle the Transfer-Encoding header through the H2 frontend. If the Transfer-Encoding header was provided as a…

  • scomurr
  • 02/20/2023
Prev
1 … 4 5 6 7 8 9 10 … 20
Next
  • keeping-data-local-fi
    Run AI Security Testing Locally: Caido Shift + Ollama for Data-Sensitive Engagements02/13/2026
  • claude_with_qwen_featured_image
    Running Claude Code with Local Models via Ollama01/30/2026
  • n8n_429_too_many_requests
    n8n and 429s – Dealing with API Rate Limits01/29/2026
  • cloudflare tunnel for on-prem
    Cloudflare Tunnel Setup for On-Prem Hosting08/31/2025
  • ssti lab 7 - featured image
    SSTI – Server-side template injection with a custom exploit03/11/2025

Let's Talk

If your organization is struggling with cybersecurity strategy, compliance, or just figuring out where to start — I'm happy to chat.
No pressure, no pitch - just a conversation to see if I can help.

Reach out directly:

[email protected] | (612) 567-2150 | LinkedIn

Copyright © 2026