daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

golang.md (2242B)


      1 ---
      2 title: "Go net/http path handling with CONNECT"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/golang.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/golang.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Go `net/http` path handling with `CONNECT`
     14 
     15 ## Historical `ServeMux` behavior
     16 
     17 In the referenced version of Go's `net/http` package, `ServeMux.Handler` canonicalizes the URL path for ordinary HTTP methods. It calls `cleanPath` and redirects the client when the clean result differs from the supplied path. This removes `.` and `..` segments and repeated slashes.<sup>[[1]](#references)</sup>
     18 
     19 For example, ordinary requests for `/flag/`, `/../flag`, or `/flag/.` can be redirected to the canonical `/flag` path, depending on the registered handler and trailing-slash behavior.<sup>[[1]](#references)</sup>
     20 
     21 The historical implementation treats `CONNECT` specially and does not run its path through this canonicalization branch. Consequently, middleware or routing logic that assumes every request has already received a cleaned path may interpret a `CONNECT` target differently from another method. Whether this produces a security bypass depends on the Go version, handler registrations, proxies, and authorization checks in the application.<sup>[[1]](#references)</sup>
     22 
     23 Use curl's `--path-as-is` option to prevent curl from normalizing the target before sending it.<sup>[[2]](#references)</sup> For example:
     24 
     25 ```bash
     26 curl --path-as-is -X CONNECT http://gofs.web.jctf.pro/../flag
     27 ```
     28 
     29 Compare the response with requests using a normal method and a canonical path. A different response is only an indicator; confirm that the discrepancy crosses an authorization boundary before reporting it.
     30 
     31 ## References
     32 
     33 - [1] [Go source - historical `ServeMux.Handler` handling of `CONNECT`](https://github.com/golang/go/blob/9bb97ea047890e900dae04202a231685492c4b18/src/net/http/server.go#L2354-L2364)
     34 - [2] [curl manual - `--path-as-is`](https://curl.se/docs/manpage.html#--path-as-is)