Exploration of browser-powered desync attacks via HTTP/3
Ayca Muvaffak · 2024
Browser -powered desync attacks is a new attack technique discovered by James Kettle in 2022. It is onekind of attack that turns the victim's web browser into a desync delivery platform. The term "browser- powered desync attack" can serve as a comprehensive label for all desync attacks that can be initiated through a web browser. Browser-Powered Desync Attacks introduced a new two different classes of desync techniques where oneof them uses browser-compatible requests to trigger a desync in between a browser and vulnerable web server, this is called Client-Side Desync attacks (CSD), and the other one uses a technique where we pause in the middle of an HTTP request. For this technique to work, first we start sending the headers, promising a body, and then just wait. We will receive a response and when we send our request body, it'll be interpreted as a new request. Then, this can cause a server time out request, but leaves the connection open for reuse. This behavior can be used to trigger both server-side and client-side desync exploits. This class of desync technique is called Pause-based Desync attacks. In this work, the research was focused on studying CSD attacks, aiming to identify vulnerable server pairswhile designing an experimental infrastructure as a simulation scan tool for vulnerability detection [2,10]. The goal of this study was to study and analyze CSD attacks, particularly their implications and risks, and implement a scan tool using a Python script to effectively detect CSD vulnerabilities in server pairs [2,10]. As part of the analysis, we have performed testing on three separate testbeds to reveal server pairs that arenot prone to CSD attacks. Why Client-Side Desync is actually a problem? One of the interesting points would be that CSD attacks pose a unique threat as they can operate within the browser where there is no need to use Burp or any other tools that worked on the lower network level. Another interesting aspect would be that the server ignores the Content Length Header and assumes it to be zero. In summary, this research work contributed to the understanding of CSD vulnerabilities, i.e. testing theapproach proposed by James Kettle (2022) originally, and offering a practical and an efficient scan tool for detecting such vulnerabilities in server pairs. The experimental infrastructure and Python script provide valuable insights for enhancing web security against this emerging threat [2,10].--Author's abstract