HTTP

HTTP injection treats the HTTP message as the dangerous primitive: when an application or an intermediary builds or parses requests and responses from untrusted input, the structure of the message itself can be subverted. This is distinct from injecting into a query or command carried inside the request; here the target is the headers, the line structure, the body framing, and the way a chain of proxies and servers agrees (or disagrees) on where one message ends.

The attacks fall into a few families. Header-value abuse trusts attacker-set headers such as Host and X-Forwarded-* for routing, access control, or link generation. CRLF injection splits a response when a carriage-return/line-feed reaches a response header. Request smuggling desynchronizes a front-end and back-end that measure request length differently. Parameter pollution supplies duplicate parameters that components resolve inconsistently.

A recurring theme is that modern servers and frameworks have hardened many of these (stripping CR/LF from header APIs, normalizing Content-Length/Transfer-Encoding), so each technique's reach depends on the exact stack, and fingerprinting the front-end and back-end is part of the work.

Techniques#

Tools#

  • Burp Suite: core platform for crafting and replaying malformed HTTP messages across these techniques.
  • Burp HTTP Request Smuggler: Burp extension for detecting and exploiting request desync.
  • curl: send raw headers, CRLF, and alternate content types from the command line.

References#

  • RFC 9110/9112 (HTTP semantics and HTTP/1.1 messaging)
  • PortSwigger Web Security Academy: HTTP request smuggling, Host header attacks

Cookie Consent

We use cookies to enhance your experience. Learn more