To achieve a successful HTTP Request Smuggling attack, one must find an area of a web application that is writeable and reflect a victim users HTTP request into that area. A web application is vulnerable to this attack when the frontend and backend servers are not able to agree on the Content-Length and Transfer-Encoding headers. Due to this, typically one HTTP request splits into two. This means that a victims HTTP request will likely append the second HTTP request sent by the attacker. This may lead to disclosure of sensitive data, such as session cookies.
Want to stay up to date in infosec? Then check out Pentest List, a curation of the latest top-rated tools and content in infosec: https://pentestlist.com
~~~
This is an educational video, gain permission from target owners before attempting anything from this tutorial. By not doing so, you risk being penalised by the computer misuse act or equivalent in your country
~~~
Burp Lab - https://portswigger.net/web-security/...
0:00 Introduction
0.47 Finding a writeable area
1:26 Setting up the payload
4:00 Exploiting the issue
5:13 Login as another user
5:38 Outro
Don't forget to subscribe and like the video for continued Cyber Security viewing!
Twitter: / turvsec
On this page of the site you can watch the video online HTTP Request Smuggling with a duration of hours minute second in good quality, which was uploaded by the user MrTurvey 06 December 2021, share the link with friends and acquaintances, this video has already been watched 3,676 times on youtube and it was liked by 47 viewers. Enjoy your viewing!