Get a Pentest and security assessment of your IT network.

Cyber Security

Researcher Demonstrates 4 New Variants of HTTP Request Smuggling Attack

A new research has identified four new variants of HTTP request smuggling attacks that work against commercial off-the-shelf web servers and HTTP proxy servers. The new variants involve using various proxy-server combinations, including Aprelium’s Abyss, Microsoft IIS, Apache, and Tomcat in the web-server mode, and Nginx, Squid, HAProxy, Caddy, and Traefik in the HTTP proxy mode. A third variant of the attack uses HTTP/1.2 to bypass WAF defenses as defined in OWASP ModSecurity Core Rule Set.

Source: https://thehackernews.com/2020/08/http-request-smuggling.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security