daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

browser-http-request-smuggling.md (2753B)


      1 ---
      2 title: "Browser HTTP Request Smuggling"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/http-request-smuggling/browser-http-request-smuggling.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/http-request-smuggling/browser-http-request-smuggling.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Browser HTTP Request Smuggling
     14 
     15 Browser-powered desynchronization, also called client-side request smuggling, uses a victim's browser to place a misframed request on a persistent connection. A subsequent request can then be interpreted out of sync by the server. Unlike classic front-end/back-end (FE/BE) request smuggling, the payload is constrained to syntax a browser can send.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     16 
     17 ## Testing considerations
     18 
     19 - Use only headers and syntax that a browser can emit through navigation, Fetch, or form submission. Traditional header obfuscations such as unusual linear whitespace (LWS), duplicate `Transfer-Encoding` (`TE`) fields, or an invalid `Content-Length` (`CL`) generally cannot be emitted by browser JavaScript.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     20 - Look for endpoints and intermediaries that reflect input, cache responses, or reuse connections. Potential impact includes cache poisoning, disclosure of front-end-injected headers, and bypasses of front-end path or method controls.
     21 - Connection reuse is essential: the crafted request must share the same HTTP/1.1 or HTTP/2 connection with a later request for the desynchronization to affect it. Connection-locked or otherwise stateful server behavior can increase the impact.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     22 - Prefer primitives that do not require custom headers, such as path confusion, query-string injection, and body shaping through form-encoded POST requests.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     23 - Distinguish a real server-side desynchronization from HTTP pipelining artifacts. Repeat the test without connection reuse and, where applicable, use the HTTP/2 nested-response technique.<sup>[[3]](#references)</sup>
     24 
     25 ## References
     26 
     27 - [1] [PortSwigger Research - Browser-Powered Desync Attacks](https://portswigger.net/research/browser-powered-desync-attacks)
     28 - [2] [PortSwigger Web Security Academy - Client-side desync](https://portswigger.net/web-security/request-smuggling/browser/client-side-desync)
     29 - [3] [PortSwigger Research - How to distinguish HTTP pipelining from request smuggling](https://portswigger.net/research/how-to-distinguish-http-pipelining-from-request-smuggling)