Back to directory
WRITEUP #388

Making desync attacks easy with TRACE

OtherDesync attackHTTP request smugglingWeb cache poisoning
by@tincho_508(Martin Doyhenard)
Program
-
Published
Mar 19, 2024
Added to HackDex
May 8, 2024
Read Full Writeuphttps://portswigger.net/research/trace-desync-attack
RELATED WRITEUPS
Gudifu: Guided Differential Fuzzing for HTTP Request Parsing Discrepancies
OtherWeb cache poisoning
Gotta cache 'em all: bending the rules of web cache exploitation
OtherWeb cache poisoning
Splitting the email atom: exploiting parsers to bypass access controls
OtherWeb cache poisoning
Data Theft in Salesforce: Manipulating Public Links
OtherSOQL injection
When Certificates Fail: A Story of Bypassed MFA in Remote Access
Other2FA / MFA bypass

Built with ❤️ by Shubham Rawat