• Stars
    star
    324
  • Rank 129,708 (Top 3 %)
  • Language
    Dockerfile
  • Created about 5 years ago
  • Updated over 1 year ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Use HTTP Smuggling Lab to learn HTTP Smuggling.

HTTP-Smuggling-Lab

HTTP-Smuggling-Lab is a lab for learning about the http request smuggling.

Installation

use docker-compose to build the lab in each directory.

Usage

Read the README.md in details in each directory.

  • In Lab1, we will chain some Reverse Proxy relations, Nginx will be the final backend, HaProxy the front load balancer, and between Nginx and HaProxy we will go through ATS6 or ATS7 based on the domain name used (dummy-host7.example.com for ATS7 and dummy-host6.example.com for ATS6).
  • Lab2 uses ATS as front server and uses LAMP and LNMP as backend servers.
  • Jetty is jetty v9.4.9. You will get more information in Jetty-README.
  • Websocket Lab is about the websocket http smuggling. You will get more information in Websocket-README.
  • HTTP/2 cleartext request smuggling please use this: h2csmuggler

You can learn more in Help you understand HTTP Smuggling in one article or the chinese version 一篇文章带你读懂 HTTP Smuggling 攻击.

Contributing

Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.

Please make sure to update tests as appropriate.

Thanks to @regilero and mengchen@Knownsec 404 Team.

License

MIT