πNew WriteupβοΈ
βββββββββββββββ
πDate: Mon, 13 Mar 2023 13:16:01 GMT
βββββββββββββββ
βοΈTitle: Checksum in golang
βββββββββββββββ
πLink: https://medium.com/p/3996fdfc1908
βββββββββββββββ
Tags: #security #go #request_response #checksums #redis
βββββββββββββββ
πDate: Mon, 13 Mar 2023 13:16:01 GMT
βββββββββββββββ
βοΈTitle: Checksum in golang
βββββββββββββββ
πLink: https://medium.com/p/3996fdfc1908
βββββββββββββββ
Tags: #security #go #request_response #checksums #redis
Medium
Checksum in golang
Using checksum to prevent processing same request multiple times
πNew WriteupβοΈ
βββββββββββββββ
πDate: Fri, 25 Aug 2023 08:47:33 GMT
βββββββββββββββ
βοΈTitle: HTB: Sau
βββββββββββββββ
πLink: https://medium.com/p/2bed96c2d6e2
βββββββββββββββ
Tags: #writeup #privesc #linux #request_basket #hackthebox
βββββββββββββββ
πDate: Fri, 25 Aug 2023 08:47:33 GMT
βββββββββββββββ
βοΈTitle: HTB: Sau
βββββββββββββββ
πLink: https://medium.com/p/2bed96c2d6e2
βββββββββββββββ
Tags: #writeup #privesc #linux #request_basket #hackthebox
Medium
HTB: Sau
Sau is an Easy machine on Hack The Box. The machine focuses on exploiting multiple vulnerabilities in order to gain access to the machineβ¦
β€· Title: Handling DELETE Requests, PATCH Requests, and Responding to URL Parameters in Node.js
ββββββββββββββββββββββββ
πͺ Author: Sheikh Mubashir
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 03 Jan 2025 17:47:42 GMT
ββββββββββββββββββββββββ
β Tags: #patch #nodejs #backend #javascript #request
ββββββββββββββββββββββββ
πͺ Author: Sheikh Mubashir
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 03 Jan 2025 17:47:42 GMT
ββββββββββββββββββββββββ
β Tags: #patch #nodejs #backend #javascript #request
Medium
Handling DELETE Requests, PATCH Requests, and Responding to URL Parameters in Node.js
When building a RESTful API, two of the most common HTTP methods youβll interact with are DELETE and PATCH. These methods allow us toβ¦
β€· Title: Request Splitting: Exploiting the Request Headers
ββββββββββββββββββββββββ
πͺ Author: Geni_Wazir
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 05 Feb 2025 17:42:32 GMT
ββββββββββββββββββββββββ
β Tags: #hacking #request_smuggling #http_request #cybersecurity #testing
ββββββββββββββββββββββββ
πͺ Author: Geni_Wazir
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 05 Feb 2025 17:42:32 GMT
ββββββββββββββββββββββββ
β Tags: #hacking #request_smuggling #http_request #cybersecurity #testing
Medium
Request Splitting: Exploiting the Request Headers
What is Request Splitting?
β€· Title: CLZero: fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 23 Feb 2025 01:10:46 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Assessment #Web AppSec #CLZero #Request Smuggling Attack
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 23 Feb 2025 01:10:46 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Assessment #Web AppSec #CLZero #Request Smuggling Attack
Penetration Testing Tools
CLZero: fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors
CLZero is a project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors.Inspired by the tool Smuggler all attack gadgets adapted from Smuggler
β€· Title: Understanding Request Smuggling: A Sneaky Vulnerability and How to Test It
ββββββββββββββββββββββββ
πͺ Author: Tanouhabib
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 01 Apr 2025 21:45:12 GMT
ββββββββββββββββββββββββ
β Tags: #request_smuggling #cybersecurity #penetration_testing #portswigger #web_vulnerabilities
ββββββββββββββββββββββββ
πͺ Author: Tanouhabib
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 01 Apr 2025 21:45:12 GMT
ββββββββββββββββββββββββ
β Tags: #request_smuggling #cybersecurity #penetration_testing #portswigger #web_vulnerabilities
Medium
Understanding Request Smuggling: A Sneaky Vulnerability and How to Test It
Subtitle (optional): βExplore the mechanics, real-world examples, and a practical lab to master this critical web attack.β
β€· Title: Apache Traffic Server Hit by Request Smuggling Vulnerability (CVE-2024-53868)
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 04 Apr 2025 00:36:26 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #Apache Traffic Server #CVE_2024_53868 #Request Smuggling Attack
ββββββββββββββββββββββββ
πͺ Author: do son
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 04 Apr 2025 00:36:26 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #Apache Traffic Server #CVE_2024_53868 #Request Smuggling Attack
Daily CyberSecurity
Apache Traffic Server Hit by Request Smuggling Vulnerability (CVE-2024-53868)
Understand CVE-2024-53868: a vulnerability in Apache Traffic Server that affects how chunked messages are processed.
β€· Title: CVE-2025-43859: Request Smuggling Vulnerability in Pythonβs h11 HTTP Library
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 27 Apr 2025 00:06:35 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #CVE_2025_43859 #CVSS 9.1 #h11 #HTTP vulnerability #Python #request smuggling #reverse proxy #Web Security
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 27 Apr 2025 00:06:35 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #CVE_2025_43859 #CVSS 9.1 #h11 #HTTP vulnerability #Python #request smuggling #reverse proxy #Web Security
Daily CyberSecurity
CVE-2025-43859: Request Smuggling Vulnerability in Pythonβs h11 HTTP Library
A CVE-2025-43859 vulnerability in Pythonβs h11 library may lead to request smuggling attacks when paired with buggy proxies. Patch to version 0.15.0 now.
β€· Title: Bypassing OTP: Unlocking Vulnerabilities & Securing Your App
ββββββββββββββββββββββββ
πͺ Author: B4LOGI
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 01 May 2025 06:03:43 GMT
ββββββββββββββββββββββββ
β Tags: #request #responses #otp_bypass #cybersecurity #infosec
ββββββββββββββββββββββββ
πͺ Author: B4LOGI
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 01 May 2025 06:03:43 GMT
ββββββββββββββββββββββββ
β Tags: #request #responses #otp_bypass #cybersecurity #infosec
Medium
π Bypassing OTP: Unlocking Vulnerabilities & Securing Your App π»π
While logged into a web application, youβve probably received an OTP (One Time Password) on your phone or email. Itβs supposed to be anβ¦
β€· Title: Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 14 May 2025 00:50:09 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 14 May 2025 00:50:09 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #Cache Poisoning #http #request smuggling #Varnish #Varnish Cache #Varnish Enterprise #Web Security
Daily CyberSecurity
Varnish Vulnerability Exposes Cache to HTTP Request Smuggling
Varnish Cache and Enterprise have a vulnerability allowing HTTP request smuggling. This can lead to cache poisoning and WAF bypass. Upgrade now!
β€· Title: HTTP/1.1 Must Die: Why This 6-Year-Old Vulnerability Is Still a Major Threat
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 08 Aug 2025 08:49:04 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #cybersecurity #HTTP/1.1 #HTTP/2 #PortSwigger #Request Smuggling #vulnerability #web security
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 08 Aug 2025 08:49:04 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #cybersecurity #HTTP/1.1 #HTTP/2 #PortSwigger #Request Smuggling #vulnerability #web security
Penetration Testing Tools
HTTP/1.1 Must Die: Why This 6-Year-Old Vulnerability Is Still a Major Threat
A 6-year-old flaw in the HTTP/1.1 protocol still enables critical request smuggling attacks. Experts are now calling for its complete and unconditional retirement.
β€· Title: HTTP Request Smuggling: Basic CL.TE Vulnerability
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 14 Aug 2025 15:31:17 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty #clte_vulnerability #http_request_smuggling #request_smuggling #chunked_transfer_encoding
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 14 Aug 2025 15:31:17 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty #clte_vulnerability #http_request_smuggling #request_smuggling #chunked_transfer_encoding
Medium
HTTP Request Smuggling: Basic CL.TE Vulnerability
Learn how CL.TE request smuggling works, why itβs dangerous, and how attackers exploit server parsing differences.
β€· Title: HTTP Request Smuggling: Basic CL.TE Vulnerability
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 15 Aug 2025 07:25:24 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty #clte_vulnerability #http_request_smuggling #request_smuggling #chunked_transfer_encoding
ββββββββββββββββββββββββ
πͺ Author: Bash Overflow
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 15 Aug 2025 07:25:24 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty #clte_vulnerability #http_request_smuggling #request_smuggling #chunked_transfer_encoding
Medium
HTTP Request Smuggling: Basic CL.TE Vulnerability
Learn how CL.TE request smuggling works, why itβs dangerous, and how attackers exploit server parsing differences.
β€· Title: Critical Flaws in Hiawatha Web Server Could Allow Authentication Bypass and RCE
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 10 Sep 2025 00:16:09 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #CERT/CC #cybersecurity #double_free #Hiawatha #open_source #rce #request smuggling #Vulnerability #web server
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 10 Sep 2025 00:16:09 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #CERT/CC #cybersecurity #double_free #Hiawatha #open_source #rce #request smuggling #Vulnerability #web server
Daily CyberSecurity
Critical Flaws in Hiawatha Web Server Could Allow Authentication Bypass and RCE
CERT/CC warns of critical flaws in the Hiawatha web server. The vulnerabilities could allow attackers to bypass authentication and hijack sessions.
β€· Title: Aiohttp Patches Seven Vulnerabilities Including High-Severity DoS Risks
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 06 Jan 2026 02:23:48 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #aiohttp #Asyncio #CVE_2025_69224 #CVE_2025_69227 #CVE_2025_69228 #Denial of Service #dos #Infinite Loop #infosec #memory exhaustion #Python #request smuggling #web development
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 06 Jan 2026 02:23:48 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #aiohttp #Asyncio #CVE_2025_69224 #CVE_2025_69227 #CVE_2025_69228 #Denial of Service #dos #Infinite Loop #infosec #memory exhaustion #Python #request smuggling #web development
Daily CyberSecurity
Aiohttp Patches Seven Vulnerabilities Including High-Severity DoS Risks
Maintainers of aiohttp, the popular asynchronous HTTP client/server framework for Python, have released a sweeping security update addressing seven distinct vulnerabilities. The update, version 3.β¦
β€· Title: Apache Traffic Server Patches βDouble-Headerβ DoS and Request Smuggling Flaws
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 03 Apr 2026 15:07:53 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #Apache Software Foundation #Apache Traffic Server #ATS #Caching #CVE_2025_58136 #CVE_2025_65114 #Denial of Service #infosec #request smuggling #security update #Web Proxy
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 03 Apr 2026 15:07:53 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #Apache Software Foundation #Apache Traffic Server #ATS #Caching #CVE_2025_58136 #CVE_2025_65114 #Denial of Service #infosec #request smuggling #security update #Web Proxy
Daily CyberSecurity
Apache Traffic Server Patches "Double-Header" DoS and Request Smuggling Flaws
Apache Traffic Server fixes two CVSS 7.5 flaws (CVE-2025-58136 & CVE-2025-65114). Prevent DoS and request smugglingβupdate to 10.1.2 or 9.2.13 now!
β€· Title: CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 12 Apr 2026 17:10:09 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #AWS IMDSv2 #Axios #Cloud Security #CVE_2026_40175 #Header injection #infosec #javascript #Node.js #Prototype Pollution #rce #request smuggling
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 12 Apr 2026 17:10:09 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #AWS IMDSv2 #Axios #Cloud Security #CVE_2026_40175 #Header injection #infosec #javascript #Node.js #Prototype Pollution #rce #request smuggling
Daily CyberSecurity
CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly
A critical CVSS 10 flaw in Axios (CVE-2026-40175) allows attackers to bypass AWS IMDSv2 and achieve RCE via header injection. Upgrade to v1.15.0 now!
β€· Title: Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 13 Apr 2026 01:00:46 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #apache Tomcat #CVE_2026_29146 #CVE_2026_34486 #Encryption Bypass #infosec #Java security #Kubernetes Security #request smuggling #vulnerability management #web server
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 13 Apr 2026 01:00:46 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #apache Tomcat #CVE_2026_29146 #CVE_2026_34486 #Encryption Bypass #infosec #Java security #Kubernetes Security #request smuggling #vulnerability management #web server
Daily CyberSecurity
Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat
Apache Tomcat discloses 10 vulnerabilities including encryption bypasses and Kubernetes token leaks. Upgrade now to secure your Java-based web applications.
β€· Title: WebSphere Remote Code Execution Defended with New IBM Security Fixes
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 30 May 2026 01:48:26 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #CVE_2026_8620 #CVE_2026_8633 #IBM Security Bulletin #IBM WebSphere #Remote Code Execution #request smuggling #Software Patch
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 30 May 2026 01:48:26 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #CVE_2026_8620 #CVE_2026_8633 #IBM Security Bulletin #IBM WebSphere #Remote Code Execution #request smuggling #Software Patch
Daily CyberSecurity
WebSphere Remote Code Execution Defended with New IBM Security Fixes
IBM released a critical WebSphere remote code execution update. Apply the request smuggling patch immediately to protect your server environment.
β€· Title: Tinyproxy Request Smuggling Flaws Expose Networks
ββββββββββββββββββββββββ
πͺ Author: Do Son
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 23 Jun 2026 02:12:44 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #CVE_2026_54387 #CVE_2026_54388 #CVE_2026_55202 #request smuggling #Tinyproxy
ββββββββββββββββββββββββ
πͺ Author: Do Son
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 23 Jun 2026 02:12:44 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #CVE_2026_54387 #CVE_2026_54388 #CVE_2026_55202 #request smuggling #Tinyproxy
Daily CyberSecurity
Tinyproxy Request Smuggling Flaws Expose Networks
Three critical Tinyproxy request smuggling vulnerabilities, including CVE-2026-54388, expose networks to severe attacks. Update your proxy servers immediately.