golang.md (2242B)
1 --- 2 title: "Go net/http path handling with CONNECT" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/golang.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/golang.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Go `net/http` path handling with `CONNECT` 14 15 ## Historical `ServeMux` behavior 16 17 In the referenced version of Go's `net/http` package, `ServeMux.Handler` canonicalizes the URL path for ordinary HTTP methods. It calls `cleanPath` and redirects the client when the clean result differs from the supplied path. This removes `.` and `..` segments and repeated slashes.<sup>[[1]](#references)</sup> 18 19 For example, ordinary requests for `/flag/`, `/../flag`, or `/flag/.` can be redirected to the canonical `/flag` path, depending on the registered handler and trailing-slash behavior.<sup>[[1]](#references)</sup> 20 21 The historical implementation treats `CONNECT` specially and does not run its path through this canonicalization branch. Consequently, middleware or routing logic that assumes every request has already received a cleaned path may interpret a `CONNECT` target differently from another method. Whether this produces a security bypass depends on the Go version, handler registrations, proxies, and authorization checks in the application.<sup>[[1]](#references)</sup> 22 23 Use curl's `--path-as-is` option to prevent curl from normalizing the target before sending it.<sup>[[2]](#references)</sup> For example: 24 25 ```bash 26 curl --path-as-is -X CONNECT http://gofs.web.jctf.pro/../flag 27 ``` 28 29 Compare the response with requests using a normal method and a canonical path. A different response is only an indicator; confirm that the discrepancy crosses an authorization boundary before reporting it. 30 31 ## References 32 33 - [1] [Go source - historical `ServeMux.Handler` handling of `CONNECT`](https://github.com/golang/go/blob/9bb97ea047890e900dae04202a231685492c4b18/src/net/http/server.go#L2354-L2364) 34 - [2] [curl manual - `--path-as-is`](https://curl.se/docs/manpage.html#--path-as-is)