HTTP Request Smuggling — CL.TE, TE.CL, TE.TE, HTTP/2 Downgrade
How two HTTP parsers disagreeing about where a request ends turns into pre-auth account takeover. HTTP/1.1 keep-alive, CL vs TE de…
Web Hacking → SSRF & Smuggling
How two HTTP parsers disagreeing about where a request ends turns into pre-auth account takeover. HTTP/1.1 keep-alive, CL vs TE de…
How a single crafted request poisons a CDN cache and serves attacker payloads to every visitor for hours. Unkeyed inputs (Host, X-…
How a "low-severity" redirect parameter turns into OAuth token theft, password-reset hijacking, an SSRF bypass, and one of the mos…
How attackers turn a harmless server-side URL fetcher into a portal straight into your VPC. Every SSRF variant: cloud metadata exf…
Complete SSRF exploitation guide — AWS IMDSv1/v2 credential theft, GCP/Azure metadata, blind SSRF with Collaborator, Redis RCE, Ku…
Deep technical guide to HTTP request smuggling — CL.TE and TE.CL desync with raw HTTP examples, HTTP/2 downgrade attacks, cache po…
Advanced web cache poisoning techniques — unkeyed headers, host header injection, cache deception, parameter cloaking, CDN-specifi…