SECURITY
search
Ctrlk
  • Enumerationchevron-right
  • Content Discovery
  • API hacking
  • CORS Misconfiguration
  • XSS
  • SSRF
  • Account take over
  • IDOR
  • Access control vulnerabilities and privilege escalation
  • HTTP Request Smuggling / HTTP Desync Attack
  • Subdomain Takeovers
  • Resources
  • 403 Bypass
  • Log4J
  • Bypassing Client-Side Controls
  • BACKUP FILES /Backup Archives:
  • Attacking Authentication
  • DNS enumeration/DNS recon-reading
  • Subdomain Enumeration-reading
  • Subdomain Takeover
  • File upload vulnerabilitieschevron-right
  • CRLF
gitbookPowered by GitBook
block-quoteOn this pagechevron-down

HTTP Request Smuggling / HTTP Desync Attack

https://book.hacktricks.xyz/pentesting-web/abusing-hop-by-hop-headersarrow-up-right

PreviousAccess control vulnerabilities and privilege escalationchevron-leftNextSubdomain Takeoverschevron-right

Last updated 2 years ago