kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Empirical Study of HTTP Request Smuggling in Open-Source Servers and Proxies
KTH, School of Electrical Engineering and Computer Science (EECS).
KTH, School of Electrical Engineering and Computer Science (EECS).
2021 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesisAlternative title
Empirisk undersökning av HTTP-förfrågningssmuggling i servrar och proxys med öppen källkod (Swedish)
Abstract [en]

During the last couple of decades cybersecurity has become increasingly important for society. As more and more of our lives turn digital, the security of the web becomes more important to its everyday users. HTTP Request Smuggling (HRS) is a vulnerability which arises when web servers and proxies interpret the length of a single HTTP request differently. In this study empirical testing was used to find parsing behaviours which could lead to HRS in six popular proxies and six servers. A literature study was conducted to compile a corpus containing requests adopting all known HRS techniques and different variations of them. A test harness was built to enable automatic sending of requests and recording of responses. The responses were then manually analysed to identify behaviours vulnerable to HRS. In total 17 vulnerable behaviours were found and by combining the proxies with the servers two almost full and three full attacks could be performed. At least one behaviour which went against the HTTP specification was found in every system tested, however, not all of these behaviours enabled HRS. In conclusion most of the proxies had strict parsing and did not accept requests which could lead to HRS. The servers however were not so strict. 

Abstract [sv]

Under de senaste årtiondena har cybersäkerhet blivit alltmer viktigt för samhället. Allt eftersom en större del av våra liv blir digitaliserade blir webbens säkerhet en viktigare aspekt för dess vardagliga användare. HTTP-förfrågningssmuggling (HFS) är en sårbarhet som uppstår när webbservrar och -proxys tolkar längden på en och samma förfrågning olika. I denna studie användes empirisk testning för att hitta tolkningsbeteenden som skulle kunna leda till HFS i sex populära proxys och sex servrar. En litteraturstudie genomfördes för att sammanställa ett korpus innehållande förfrågningar med alla kända HFS tekniker och olika versioner av dem. Ett testskelett byggdes för att möjliggöra att skicka förfrågningar automatiskt och dokumentera svaren. Svaren analyserades sen manuellt för att identifiera beteenden som var sårbara för HFS. Totalt hittades 17 olika sårbara beteenden och genom att kombinera proxyna med servrarna hittades två nästan fulla och tre fulla attacker som kunde genomföras. Minst ett beteende som går emot HTTP-specifikationen hittades i varje system. Däremot kunde inte alla dessa beteenden användas till HFS. De flesta proxyna som testades var strikta när de tolkade förfrågningar och accepterade inte förfrågningar som kunde leda till HFS. Servrarna var dock inte lika strikta.

Place, publisher, year, edition, pages
2021. , p. 44
Series
TRITA-EECS-EX ; 2021:449
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:kth:diva-302371OAI: oai:DiVA.org:kth-302371DiVA, id: diva2:1596031
Subject / course
Computer Science
Educational program
Master of Science in Engineering - Computer Science and Technology
Supervisors
Examiners
Available from: 2021-09-22 Created: 2021-09-21 Last updated: 2022-06-25Bibliographically approved

Open Access in DiVA

fulltext(672 kB)4408 downloads
File information
File name FULLTEXT01.pdfFile size 672 kBChecksum SHA-512
b3ea94d604c26b9f3e7257b3f835b01d3c717d09b290e75e45e5d1f03f3db75f8b1d6d2b88d1ab1f895553ae1dfabd07eb7f7d53cce46916de1f244df59f5f6a
Type fulltextMimetype application/pdf

By organisation
School of Electrical Engineering and Computer Science (EECS)
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 4416 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 3976 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf