Request Smuggling Via HTTP/2 Cleartext in the Wild: Empirical Testing with Differential Fuzzing
Yingbo Li, Zhensong Huai, Xiaolong Yan, Jing Liu · 2023
The Request Smuggling Via HTTP/2 Cleartext (H2C Smuggling) attacks exploit vulnerabilities in the handling of HTTP request headers by proxy servers, allowing attackers to bypass security measures such as WAFs and gain unauthorized access to internal resources. We developed an experimental infrastructure that utilizes a grammar-based differential fuzzer to test 18 widely-used Connect Direct Network (CDN)/Web Application Firewall (WAF)/Load Balancing technologies. Through this testing, we identified vulnerabilities that can be exploited to carry out H2C Smuggling attacks.