Burp Suite User Forum

Create new post

HTTP Request Smuggler

[ | Last updated: Feb 11, 2022 02:04PM UTC

I used HTTP Request Smuggler and i checked the result with flow extention and i want to know if that a web application is vulnerable to http smuggle attack should the response of request be 200 or it can be 501,301,400?

Alex, PortSwigger Agent | Last updated: Feb 14, 2022 04:35PM UTC

Hi, Thanks for your post. I would refer to the following documentation on HTTP Request Smuggling: - https://portswigger.net/web-security/request-smuggling - https://portswigger.net/web-security/request-smuggling/finding - https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn Thanks

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.