Burp Suite User Forum

Create new post

http request smuggling

Bablu | Last updated: Dec 08, 2020 05:20AM UTC

Hi dear, can you please tell me why I am still getting this vulnerability in my application. I have disabled http request smuggling in IIS server.

Hannah, PortSwigger Agent | Last updated: Dec 08, 2020 09:27AM UTC

Hi The issue raised in Burp should provide you with some example requests and responses on how this vulnerability was triggered. You can use those to try and replicate the issue, to manually confirm that it is present. We have a whole web academy topic dedicated to HTTP Request Smuggling, as well as some whitepapers, so if you want to find out more information about it or try out a request smuggling attack in a lab scenario, you can. You can find these here: - https://portswigger.net/web-security/request-smuggling - https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn - https://portswigger.net/research/http-desync-attacks-what-happened-next - https://portswigger.net/research/breaking-the-chains-on-http-request-smuggler

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.