A rapid HTTP downgrade smuggling scanner written in Go.
-
Updated
May 16, 2024 - Go
A rapid HTTP downgrade smuggling scanner written in Go.
A curated list of awesome blogs and tools about HTTP request smuggling attacks. Feel free to contribute! 🍻
HTTP request smuggling attack helper/CLI tools to manipulate HTTP packets
Blog about HTTP Request Smuggling, including a demo application.
Automated Discovery of Parsing Discrepancy Related Bypasses in Web Application Firewalls Using HTTP Request Fuzzing.
A lab-driven course on breaking web applications and explaining how to fix them — 491 notes, 36 reproducible labs, mapped to OWASP WSTG and the PortSwigger Top 10 Web Hacking Techniques.
Burp extension to calculate the byte size of selections made in text windows
Compliance evidence for HTTP header security. Assesses both sides of the exchange — the request headers an attacker manipulates and the response headers you must send — confirms every finding with a second probe, maps it to OWASP ASVS 5.0 and PCI DSS 4.0.1, and reports what it could not assess instead of counting it as a pass.
An HTTP/1.1 parser with a hard memory ceiling: 2352 bytes per request, 48-byte deepest stack frame, zero heap allocations - each enforced by the build rather than promised in prose.
Burp Suite Pro extension (Montoya API): HTTP request-smuggling / desync hypothesis scanner with a framing-aware, oracle-free classifier and Burp Collaborator OOB (SSRF) detection.
Detect and confirm HTTP/S desync vulnerabilities
HTTP Request Smuggling & Client-Side Desync framework for Exchange OWA. CL.TE/TE.CL detection, email spoofing, cache poisoning.
Lab didático de HTTP Request Smuggling (TE.CL) — servidor vulnerável em C + exploits Python
Phage: an evolutionary HTTP/3-to-HTTP/1 request-smuggling desync fuzzer. A fork of CyberArk QuicDrawH3 that adds a MAP-Elites engine, QUIC-state genes (bare FIN, RESET), and H3/H2 downgrade operators on top of the Quic-Fin-Sync primitive.
8-phase cache & transport attack scanner — cache poison, request smuggling, H2C, CDN bypass
automatic HTTP request smuggling vulnerability detection
Байт-точный пробер HTTP request smuggling / desync на сырых сокетах. C++17, POSIX, ноль зависимостей. Authorized-only.
CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers 7.0/8.0/8.5/9.0/10.0/10.1/11.0 lines.
To associate your repository with the request-smuggling topic, visit your repo's landing page and select "manage topics."