A rapid HTTP downgrade smuggling scanner written in Go.
-
Updated
May 16, 2024 - Go
A rapid HTTP downgrade smuggling scanner written in Go.
A curated list of awesome blogs and tools about HTTP request smuggling attacks. Feel free to contribute! 🍻
HTTP request smuggling attack helper/CLI tools to manipulate HTTP packets
Blog about HTTP Request Smuggling, including a demo application.
A lab-driven course on breaking web applications and explaining how to fix them — 491 notes, 36 reproducible labs, mapped to OWASP WSTG and the PortSwigger Top 10 Web Hacking Techniques.
Automated Discovery of Parsing Discrepancy Related Bypasses in Web Application Firewalls Using HTTP Request Fuzzing.
Differential fuzzer that finds HTTP parser discrepancies across 54 servers to uncover request-smuggling primitives.
Burp extension to calculate the byte size of selections made in text windows
Compliance evidence for HTTP header security. Assesses both sides of the exchange — the request headers an attacker manipulates and the response headers you must send — confirms every finding with a second probe, maps it to OWASP ASVS 5.0 and PCI DSS 4.0.1, and reports what it could not assess instead of counting it as a pass.
Burp Suite Pro extension (Montoya API): HTTP request-smuggling / desync hypothesis scanner with a framing-aware, oracle-free classifier and Burp Collaborator OOB (SSRF) detection.
Phage: an evolutionary HTTP/3-to-HTTP/1 request-smuggling desync fuzzer. A fork of CyberArk QuicDrawH3 that adds a MAP-Elites engine, QUIC-state genes (bare FIN, RESET), and H3/H2 downgrade operators on top of the Quic-Fin-Sync primitive.
An HTTP/1.1 parser with a hard memory ceiling: 2352 bytes per request, 48-byte deepest stack frame, zero heap allocations - each enforced by the build rather than promised in prose.
HTTP Request Smuggling & Client-Side Desync framework for Exchange OWA. CL.TE/TE.CL detection, email spoofing, cache poisoning.
sRX87 is SSL/TLS reconnaissance and exploitation framework. It runs 12 stages: transport recon, cert parsing, cipher enumeration, real crypto oracles, HTTP smuggling, auth bypass, SSRF, cloud metadata, CVE correlation, and 20-format reporting.
Lab didático de HTTP Request Smuggling (TE.CL) — servidor vulnerável em C + exploits Python
Detect and confirm HTTP/S desync vulnerabilities
CVE-2026-2332 and 4 more 2026 Jetty CVEs: which does your Jetty (or Spring Boot) build hit, and does the fixed version Jetty names even exist on Maven Central? For 9.4/10/11 EOL lines the answer is 'see details for availability' = 404.
L7 reverse proxy + load balancer from raw TCP sockets in Go, zero deps. A measured lab notebook.
To associate your repository with the request-smuggling topic, visit your repo's landing page and select "manage topics."