Skip to content
  • Home
  • LinkedIn
  • Contact
scomurr.com
  • Home
  • LinkedIn
  • Contact
scomurr logo

  • Security, Web Attacks

HTTP Request Smuggling – Identifying Frontend Request Rewriting and Exploiting

This is the 7th blog post in the series I am publishing dealing with Request Smuggling or Desync vulnerabilities and attacks. These posts align to the PortSwigger Web Security Academy labs (here). Just as in the past two posts, this…

  • scomurr
  • 01/02/2023
  • Security, Web Attacks

HTTP Request Smuggling – Bypassing Frontend Security Controls Part 2

This is the 6th blog post in the series I am publishing dealing with Request Smuggling or Desync vulnerabilities and attacks. These posts align to the PortSwigger Web Security Academy labs (here). The first four posts deal with theory and…

  • scomurr
  • 12/23/2022
  • Security, Web Attacks

HTTP Request Smuggling – Bypassing Frontend Security Controls

This is the next blog post in the series I am publishing dealing with Request Smuggling or Desync vulnerabilities and attacks. These posts align to the PortSwigger Web Security Academy labs (here). The first four posts deal with theory and…

  • scomurr
  • 12/21/2022
  • Security, Web Attacks

HTTP Request Smuggling – Finding and Exploiting via Differential Responses

This is the continuation of the series I am publishing that aligns to the PortSwigger Web Security Academy labs on Request Smuggling or Desync vulnerabilities and attacks (here). In this post, I will be dealing with identifying and exploiting these…

  • scomurr
  • 12/19/2022
  • Security, Web Attacks

HTTP Request Smuggling – Obfuscated TE Header

This is blog post #3 in a series that covers HTTP Request Smuggling or HTTP Desync attacks. This post focuses on the 3rd HTTP Request Smuggling lab on the PortSwigger Web Security Academy focused on obfuscating the TE header. The…

  • scomurr
  • 12/16/2022
Prev
1 … 6 7 8 9 10 11 12 … 20
Next
  • keeping-data-local-fi
    Run AI Security Testing Locally: Caido Shift + Ollama for Data-Sensitive Engagements02/13/2026
  • claude_with_qwen_featured_image
    Running Claude Code with Local Models via Ollama01/30/2026
  • n8n_429_too_many_requests
    n8n and 429s – Dealing with API Rate Limits01/29/2026
  • cloudflare tunnel for on-prem
    Cloudflare Tunnel Setup for On-Prem Hosting08/31/2025
  • ssti lab 7 - featured image
    SSTI – Server-side template injection with a custom exploit03/11/2025

Let's Talk

If your organization is struggling with cybersecurity strategy, compliance, or just figuring out where to start — I'm happy to chat.
No pressure, no pitch - just a conversation to see if I can help.

Reach out directly:

[email protected] | (612) 567-2150 | LinkedIn

Copyright © 2026