browser-http-request-smuggling.md (2753B)
1 --- 2 title: "Browser HTTP Request Smuggling" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/http-request-smuggling/browser-http-request-smuggling.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/http-request-smuggling/browser-http-request-smuggling.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Browser HTTP Request Smuggling 14 15 Browser-powered desynchronization, also called client-side request smuggling, uses a victim's browser to place a misframed request on a persistent connection. A subsequent request can then be interpreted out of sync by the server. Unlike classic front-end/back-end (FE/BE) request smuggling, the payload is constrained to syntax a browser can send.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 16 17 ## Testing considerations 18 19 - Use only headers and syntax that a browser can emit through navigation, Fetch, or form submission. Traditional header obfuscations such as unusual linear whitespace (LWS), duplicate `Transfer-Encoding` (`TE`) fields, or an invalid `Content-Length` (`CL`) generally cannot be emitted by browser JavaScript.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 20 - Look for endpoints and intermediaries that reflect input, cache responses, or reuse connections. Potential impact includes cache poisoning, disclosure of front-end-injected headers, and bypasses of front-end path or method controls. 21 - Connection reuse is essential: the crafted request must share the same HTTP/1.1 or HTTP/2 connection with a later request for the desynchronization to affect it. Connection-locked or otherwise stateful server behavior can increase the impact.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 22 - Prefer primitives that do not require custom headers, such as path confusion, query-string injection, and body shaping through form-encoded POST requests.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 23 - Distinguish a real server-side desynchronization from HTTP pipelining artifacts. Repeat the test without connection reuse and, where applicable, use the HTTP/2 nested-response technique.<sup>[[3]](#references)</sup> 24 25 ## References 26 27 - [1] [PortSwigger Research - Browser-Powered Desync Attacks](https://portswigger.net/research/browser-powered-desync-attacks) 28 - [2] [PortSwigger Web Security Academy - Client-side desync](https://portswigger.net/web-security/request-smuggling/browser/client-side-desync) 29 - [3] [PortSwigger Research - How to distinguish HTTP pipelining from request smuggling](https://portswigger.net/research/how-to-distinguish-http-pipelining-from-request-smuggling)