Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

h2c Smuggling: Request Smuggling Via HTTP/2 Cleartext (h2c)

Summary

Jake Miller demonstrates how upgrading HTTP/1.1 connections to HTTP/2 cleartext (h2c) can smuggle requests past reverse proxy access controls and establish long-lived back-end access.
Published
Collected

original ↗

Related coverage

back