Open cardosec

Case E53F5A · Web AppSec · L5 Expert

HTTP Request Smuggling

Practise as: Explain it · Deep dive · Interview

Interview questionExplain how HTTP request smuggling works across a proxy and a backend, and how HTTP/2 changes it.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Front-end and back-end disagree on where a request ends, so leftover bytes prefix the next request on a reused connection
  2. CL.TE and TE.CL: one tier honours Content-Length, the other chunked Transfer-Encoding; TE.TE hides TE via header obfuscation
  3. H2 downgrade (H2.CL, H2.TE): the proxy rewrites HTTP/2 to HTTP/1.1 and forwards attacker-set length or CRLF-injected headers
  4. Impact: bypass front-end access rules, capture other users requests and cookies, poison caches, desync the response queue
  5. Fix: HTTP/2 end to end, reject requests with both CL and TE or malformed TE, normalize at the edge, limit backend reuse

If the interviewer pushes back

  • How would you confirm a CL.TE desync on production using timing, without hijacking a real user request?
  • What is a client-side desync, and why does it not need a front-end proxy at all?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.