Episode #846 Quiz
HTTP REQUEST SMUGGLING
Date: 2021-11-23 | Length: 1.75 hrs | Episode page at twit.tv
About this episode
The episode examines HTTP request smuggling, where front-end and back-end servers disagree on request boundaries because of conflicting Content-Length and Transfer-Encoding handling. Attackers can smuggle hidden requests past proxies, caches, and web application firewalls, enabling cache poisoning, session hijacking, XSS, and WAF bypasses. Mitigations require consistent parsing and strict normalization.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.