Umbra Wiki attack-pattern attack-pattern/CAPEC-33
Back to wiki

CAPEC-33 — HTTP Request Smuggling

provenance: imported · CWE: CWE-444

CAPEC-33: HTTP Request Smuggling

MITRE CAPEC attack pattern

Status Stable
Typical severity High
Likelihood of attack Medium
Catalogue CAPEC 3.9 (2023-01-24)

Description

An adversary abuses the flexibility and discrepancies in the parsing and interpretation of HTTP Request messages using various HTTP headers, request-line and body parameters as well as message sizes (denoted by the end of message signaled by a given HTTP header) by different intermediary HTTP agents (e.g., load balancer, reverse proxy, web caching proxies, application firewalls, etc.) to secretly send unauthorized and malicious HTTP requests to a back-end HTTP agent (e.g., web server). See CanPrecede relationships for possible consequences.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-444

Prerequisites

  • An additional intermediary HTTP agent such as an application firewall or a web caching proxy between the adversary and the second agent such as a web server, that sends multiple HTTP messages over same network connection.
  • Differences in the way the two HTTP agents parse and interpret HTTP requests and its headers.
  • HTTP agents running on HTTP/1.1 that allow for Keep Alive mode, Pipelined queries, and Chunked queries and responses.

Skills required

  • Medium: Detailed knowledge on HTTP protocol: request and response messages structure and usage of specific headers.
  • Medium: Detailed knowledge on how specific HTTP agents receive, send, process, interpret, and parse a variety of HTTP messages and headers.
  • Medium: Possess knowledge on the exact details in the discrepancies between several targeted HTTP agents in path of an HTTP message in parsing its message structure and individual headers.

Consequences

  • Confidentiality, Integrity, Availability: Execute Unauthorized Commands
  • Confidentiality, Access Control, Authorization: Gain Privileges
  • Integrity: Modify Data

Mitigations

  • Design: evaluate HTTP agents prior to deployment for parsing/interpretation discrepancies.
  • Configuration: front-end HTTP agents notice ambiguous requests.
  • Configuration: back-end HTTP agents reject ambiguous requests and close the network connection.
  • Configuration: Disable reuse of back-end connections.
  • Configuration: Use HTTP/2 for back-end connections.
  • Configuration: Use the same web server software for front-end and back-end server.
  • Implementation: Utilize a Web Application Firewall (WAF) that has built-in mitigation to detect abnormal requests/responses.
  • Configuration: Prioritize Transfer-Encoding header over Content-Length, whenever an HTTP message contains both.

Source