h2c Smuggling: Request Smuggling Via HTTP/2 Cleartext (h2c)
bishopfox.com | blog | #web-security | #request-smuggling | #vulnerability | #http2 | #h2c | #reverse-proxy
Summary
Jake Miller demonstrates how upgrading HTTP/1.1 connections to HTTP/2 cleartext (h2c) can smuggle requests past reverse proxy access controls and establish long-lived back-end access.
- Published
- Collected
Skip to content