Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ Researcher Discovers New 'HTTP Request Smuggling Attack' Variants

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Researcher Discovers New 'HTTP Request Smuggling Attack' Variants


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: it.slashdot.org

Some scary new variants of "HTTP request smuggling" have been discovered by Amit Klein, VP of security research at SafeBreach, reports Security Week: Specifically, an HTTP request smuggling attack, which can be launched remotely over the internet, can allow a hacker to bypass security controls, gain access to sensitive data, and compromise other users of the targeted app. While the attack method has been known for more than a decade, it still hasn't been fully mitigated. Klein has managed to identify five new attack variants and he has released proof-of-concept (PoC) exploits. He demonstrated his findings using the Abyss X1 web server from Aprelium and the Squid caching and forwarding HTTP web proxy. The developers of Abyss and Squid have been notified of the vulnerabilities exploited by Klein during his research, and they have released patches and mitigations. One of the attacks bypasses the OWASP ModSecurity Core Rule Set (CRS), which provides generic attack detection rules for ModSecurity or other web application firewalls. OWASP has also released fixes after being notified. Klein told SecurityWeek ahead of his talk on HTTP request smuggling at the Black Hat conference that an attacker needs to find combinations of web servers and proxy servers with "matching" vulnerabilities in order to launch an attack, which makes it difficult to determine exactly how many servers are impacted. However, an attacker can simply try to launch an attack to determine if a system is vulnerable. "The attack is not demanding resource-wise, so there's no downside to simply trying it," Klein said. In his research, he demonstrated a web cache poisoning attack, in which the attacker forces the proxy server to cache the content of one URL for a request of a different URL. He says attacks can be launched en-masse through a proxy server against multiple different web servers or against multiple proxy servers... While there haven't been any reports of HTTP request smuggling being used in the wild, Klein has pointed out that attacks may have been launched but were not detected by the target.

Read more of this story at Slashdot.

...



๐Ÿ“Œ Researcher Discovers New HTTP Request Smuggling Attack Variants


๐Ÿ“ˆ 76.83 Punkte

๐Ÿ“Œ Researcher Discovers New 'HTTP Request Smuggling Attack' Variants


๐Ÿ“ˆ 76.83 Punkte

๐Ÿ“Œ Researcher Demonstrates 4 New Variants of HTTP Request Smuggling Attack


๐Ÿ“ˆ 60.37 Punkte

๐Ÿ“Œ Puma Gem up to 3.12.4/4.3.3 on Ruby HTTP Smuggling request smuggling


๐Ÿ“ˆ 39.75 Punkte

๐Ÿ“Œ EvilNet - Network Attack Wifi Attack Vlan Attack Arp Attack Mac Attack Attack Revealed Etc...


๐Ÿ“ˆ 32.17 Punkte

๐Ÿ“Œ Undertow HTTP Request HTTP/1.x request smuggling


๐Ÿ“ˆ 31.36 Punkte

๐Ÿ“Œ HTTP Request Smuggler - Extension For Burp Suite Designed To Help You Launch HTTP Request Smuggling Attacks


๐Ÿ“ˆ 31.36 Punkte

๐Ÿ“Œ Google researcher discovers new type of Windows security weakness


๐Ÿ“ˆ 31.04 Punkte

๐Ÿ“Œ Virus Bulletin researcher discovers new Lord exploit kit


๐Ÿ“ˆ 31.04 Punkte

๐Ÿ“Œ Google researcher discovers new iOS security system


๐Ÿ“ˆ 31.04 Punkte

๐Ÿ“Œ CLZero - A Project For Fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors


๐Ÿ“ˆ 29.07 Punkte

๐Ÿ“Œ Undertow up to 1.3.30/1.4.16 HTTP Request Header Request Smuggling privilege escalation


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ JetBrains Ktor up to 1.4.2 HTTP Request request smuggling


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ CVE-2022-2466 | Quarkus 2.10.x HTTP Request request smuggling (ID 26748)


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ CVE-2023-25950 | HAProxy up to 2.6.7/2.7.0 HTTP Request request smuggling


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ CVE-2023-46137 | Twisted up to 23.9.x HTTP Request request smuggling (GHSA-xc8x-vp79-p3wm)


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ CVE-2019-15605 | Node.js 10/12/13 Transfer Encoding HTTP Request request smuggling (RHSA-2020:0573)


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ CVE-2020-1935 | Apache Tomcat up to 7.0.99/8.5.50/9.0.30 Header Parsing HTTP Request request smuggling (USN-4448-1)


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ CVE-2024-27922 | tomphttp bare-server-node HTTP Request request smuggling (GHSA-86fc-f9gr-v533)


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ Undertow bis 1.3.30/1.4.16 HTTP Request Header Request Smuggling erweiterte Rechte


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ Netty up to 4.1.41 Whitespace HTTP Request Request Smuggling privilege escalation


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ Google Go up to 1.12.9/1.13.0 HTTP Request Request Smuggling privilege escalation


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ Squid Web Proxy up to 4.11/5.0.2 ContentLengthInterpreter.cc HTTP Request request smuggling


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ Apache HTTP Server up to 2.4.43 HTTP2 Request request smuggling


๐Ÿ“ˆ 28.7 Punkte

๐Ÿ“Œ Researcher Discovers Android Zero-Day Affecting Recent Smartphones Under Active Exploit


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ Researcher Discovers Critical Linux WiFi Vulnerability That Existed For Four Years


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ Researcher Discovers Critical Vulnerability and Was Awarded $100,000


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ Googleโ€™s bug-tracking system contained its own vulnerabilities, researcher discovers


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ Security Researcher Discovers macOS Flaw, Refuses to Share Details with Apple


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ Getting Cool Vanity License Plate 'NULL' Is Not Really a Cool Idea, Infosec Researcher Discovers


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ Security researcher accidentally discovers Windows 7 and Windows Server 2008 zero-day


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ Researcher Discovers Susceptibility Affecting Numerous Linux Marketplaces


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ Researcher Discovers Backdoor In Toyota Supplier Management Network


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ Better Than JPEG? Researcher Discovers That Stable Diffusion Can Compress Images


๐Ÿ“ˆ 28.12 Punkte

๐Ÿ“Œ New HTTP Request Smuggling Attacks Target Web Browsers


๐Ÿ“ˆ 26.63 Punkte











matomo