3937 | Write up of two HTTP Requests Smuggling |
HTTP request smuggling |
NA |
C1h2e1 (@C1h2e11) |
Bug Bounty | 2019-09-07 | 2023-06-13 |
3924 | HTTP Request Smuggling CL.TE |
HTTP request smuggling |
NA |
memN0ps (@memN0ps) |
Bug Bounty | 2019-09-13 | 2023-06-13 |
3809 | How Did Tons of People Like Me on Tinder? |
HTTP request smuggling |
NA |
Mustafa iran (@Mustafaran) |
Bug Bounty | 2019-11-25 | 2023-06-13 |
3799 | HTTP Request Smuggling + IDOR |
HTTP request smuggling
IDOR |
NA |
hipotermia (@_hipotermia_) |
Bug Bounty | 2019-12-05 | 2023-06-13 |
3738 | Account takeover via HTTP Request Smuggling |
HTTP request smuggling
Account takeover
Open redirect
Internal header disclosure |
NA |
hipotermia (@_hipotermia_) |
Bug Bounty | 2020-01-03 | 2023-06-13 |
3701 | Escalating reflected XSS with HTTP Smuggling |
Reflected XSS
HTTP request smuggling |
NA |
Hazana (@HazanaSec) |
Bug Bounty | 2020-01-27 | 2023-06-13 |
3123 | The Powerful HTTP Request Smuggling 💪 |
HTTP Request Smuggling |
NA |
Ricardo Iramar dos Santos (@ricardo_iramar) |
Bug Bounty | 2020-10-01 | 2023-06-13 |
3084 | IBM Datapower Exploit CVE-2020-5014 |
SSRF
HTTP Request Smuggling |
IBM |
Thomas Cope |
Bug Bounty | 2020-10-21 | 2023-06-13 |
3034 | Smuggling an (Un)exploitable XSS |
HTTP Request Smuggling
XSS |
NA |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2020-11-13 | 2023-06-13 |
2868 | Get paid by smuggling, the legal way |
HTTP Request Smuggling |
NA |
James Ling (@James_puppykok) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2729 | Exploiting HTTP Request Smuggling (TE.CL)— XSS to website takeover |
HTTP request smuggling
XSS |
NA |
Kleiton Kurti (@kleiton0x7e) |
Bug Bounty | 2021-03-09 | 2023-06-13 |
2705 | H2C Smuggling in the Wild |
HTTP request smuggling |
NA |
Sean Yeoh (@seanyeoh) |
Bug Bounty | 2021-03-18 | 2023-06-13 |
2626 | Harvesting Active Directory credentials via HTTP Request Smuggling |
HTTP request smuggling |
NA |
Tijme Gommers (@tijme) |
Bug Bounty | 2021-04-19 | 2023-06-13 |
2276 | I owe your Request | HTTP Request Smuggling leads to Full Accounts takeover |
HTTP Request Smuggling |
NA |
Muhammad Adel (@ItsFadinG_) |
Bug Bounty | 2021-08-30 | 2023-06-13 |
2092 | Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond |
HTTP Header Smuggling
HTTP Request Smuggling |
NA |
Daniel Thatcher (@_danielthatcher) |
Bug Bounty | 2021-11-10 | 2023-06-13 |
2076 | T-Reqs: HTTP Request Smuggling with Differential Fuzzing |
HTTP Request Smuggling |
NA |
Bahruz Jabiyev (@BahruzJabiyev) |
Bug Bounty | 2021-11-15 | 2023-06-13 |
1833 | ICMAD SAP Vulnerabilities (CVE-2022-22536, CVE-2022-22532 & CVE-2022-22533) |
HTTP request smuggling
Memory leak
DoS
Memory corruption |
SAP |
SAP Product Security Response team |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1775 | HDiff: A Semi-automatic Framework for Discovering Semantic Gap Attack in HTTP Implementations |
HTTP request smuggling
DoS
Semantic gap attacks |
NA |
Kaiwen Shen (@m0xiaoxi) |
Bug Bounty | 2022-03-01 | 2023-06-13 |
1657 | HTTP Request Smuggling on business.apple.com and Others. |
HTTP request smuggling |
Apple |
Stealthy (@stealthybugs) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1254 | Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling |
HTTP Request Smuggling
Desync attack |
AWS
Amazon
Akamai
Cisco
Verisign
Pulse Secure
Varnish |
James Kettle (@albinowax) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1253 | Advanced Inter-Process Desynchronization in SAP’s HTTP Server |
Memory corruption
RCE
HTTP Request Smuggling
Web cache poisoning
Desync attack |
SAP |
Martin Doyhenard (@tincho_508) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1244 | FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies |
HTTP Request Smuggling
DoS |
NA |
Bahruz Jabiyev (@BahruzJabiyev) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1121 | How to turn security research into profit: a CL.0 case study |
HTTP request smuggling
Desync attack |
NA |
James Kettle (@albinowax) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1078 | HTTP Desync Attack (Request Smuggling) - Mass Account Takeover at a Cryptocurrency based asset and 121 other websites |
HTTP Request Smuggling
Desync attack |
NA |
Ankit Singh (@AnkitCuriosity) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1072 | How an Akamai misconfiguration earned us USD 46.000 |
HTTP request smuggling |
Akamai
Microsoft
Apple |
Francesco Mariani (@_medusa_1_) |
Bug Bounty | 2022-09-17 | 2023-06-13 |