T-Reqs: HTTP Request Smuggling with Differential Fuzzing

49Citations
Citations of this article
34Readers
Mendeley users who have this article in their library.
Get full text

Abstract

HTTP Request Smuggling (HRS) is an attack that exploits the HTTP processing discrepancies between two servers deployed in a proxy-origin configuration, allowing attackers to smuggle hidden requests through the proxy. While this idea is not new, HRS is soaring in popularity due to recently revealed novel exploitation techniques and real-life abuse scenarios. In this work, we step back from the highly-specific exploits hogging the spotlight, and present the first work that systematically explores HRS within a scientific framework. We design an experiment infrastructure powered by a novel grammar-based differential fuzzer, test 10 popular server/proxy/CDN technologies in combinations, identify pairs that result in processing discrepancies, and discover exploits that lead to HRS. Our experiment reveals previously unknown ways to manipulate HTTP requests for exploitation, and for the first time documents the server pairs prone to HRS.

Cite

CITATION STYLE

APA

Jabiyev, B., Sprecher, S., Onarlioglu, K., & Kirda, E. (2021). T-Reqs: HTTP Request Smuggling with Differential Fuzzing. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 1805–1820). Association for Computing Machinery. https://doi.org/10.1145/3460120.3485384

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free