Burp Suite User Forum

Create new post

why there is an empty line after Content-Length header in http smuggle attacks?

[ | Last updated: Mar 21, 2022 06:09PM UTC

for example : POST /search HTTP/1.1 Host: normal-website.com Content-Type: application/x-www-form-urlencoded Content-Length: 11 q=smuggling So the length of 'q=smugglingis' is 11. why there is an empty line after 'Content-Length: 11'?

[ | Last updated: Mar 21, 2022 06:13PM UTC

oops,i find the answer after posting???? Each chunk consists of the chunk size in bytes (expressed in hexadecimal), followed by a newline, followed by the chunk contents. The message is terminated with a chunk of size zero. For example:

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.