During the last couple of decades cybersecurity has become increasingly important for society. As more and more of our lives turn digital, the security of the web becomes more important to its everyday users. HTTP Request Smuggling (HRS) is a vulnerability which arises when web servers and proxies interpret the length of a single HTTP request differently. In this study empirical testing was used to find parsing behaviours which could lead to HRS in six popular proxies and six servers. A literature study was conducted to compile a corpus containing requests adopting all known HRS techniques and different variations of them. A test harness was built to enable automatic sending of requests and recording of responses. The responses were then manually analysed to identify behaviours vulnerable to HRS. In total 17 vulnerable behaviours were found and by combining the proxies with the servers two almost full and three full attacks could be performed. At least one behaviour which went against the HTTP specification was found in every system tested, however, not all of these behaviours enabled HRS. In conclusion most of the proxies had strict parsing and did not accept requests which could lead to HRS. The servers however were not so strict.
Under de senaste årtiondena har cybersäkerhet blivit alltmer viktigt för samhället. Allt eftersom en större del av våra liv blir digitaliserade blir webbens säkerhet en viktigare aspekt för dess vardagliga användare. HTTP-förfrågningssmuggling (HFS) är en sårbarhet som uppstår när webbservrar och -proxys tolkar längden på en och samma förfrågning olika. I denna studie användes empirisk testning för att hitta tolkningsbeteenden som skulle kunna leda till HFS i sex populära proxys och sex servrar. En litteraturstudie genomfördes för att sammanställa ett korpus innehållande förfrågningar med alla kända HFS tekniker och olika versioner av dem. Ett testskelett byggdes för att möjliggöra att skicka förfrågningar automatiskt och dokumentera svaren. Svaren analyserades sen manuellt för att identifiera beteenden som var sårbara för HFS. Totalt hittades 17 olika sårbara beteenden och genom att kombinera proxyna med servrarna hittades två nästan fulla och tre fulla attacker som kunde genomföras. Minst ett beteende som går emot HTTP-specifikationen hittades i varje system. Däremot kunde inte alla dessa beteenden användas till HFS. De flesta proxyna som testades var strikta när de tolkade förfrågningar och accepterade inte förfrågningar som kunde leda till HFS. Servrarna var dock inte lika strikta.