vulns.co
/
GKData.io MCP

Back to Playbooks

HTTP Request Smuggling

Exploit disagreements between a front-end proxy and back-end server on where one request ends, to poison the connection of the next user.

Tags: smuggling, desync, http, proxy

Level: advanced

Method

  1. Identify a desync

    Send crafted Content-Length / Transfer-Encoding combinations and time the responses. A delay on a TE.CL/CL.TE probe indicates the back-end is waiting for bytes that never come.

    python3 smuggler.py -u https://target.com/

    Tools: smuggler, Burp Suite

  2. Confirm CL.TE vs TE.CL

    Use Burp Repeater with HTTP/1.1 and disabled auto-Content-Length. Confirm by smuggling a partial request that prepends to the victim's next request.

    Tools: Burp Suite

  3. Try H2.CL / H2.TE downgrade

    If the edge speaks HTTP/2 but downgrades to HTTP/1.1 upstream, smuggle via ambiguous h2 headers. Also test h2c upgrade for access-control bypass.

    python3 h2csmuggler.py -x https://edge.target.com http://target/admin

    Tools: h2csmuggler

  4. Weaponize

    Escalate to capturing other users' requests (session theft), bypassing front-end auth to reach internal paths, or reflected-XSS delivery via the poisoned socket.

    Tools: Burp Suite

Field notes

  • Always use Burp's 'HTTP Request Smuggler' extension for reliable, non-destructive probes.
  • Smuggling can affect other real users - keep payloads benign and coordinate with the program.
  • Retry: results are timing/queue dependent, not always first-shot.

References