Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

HTTP/2 - The Sequel is Always Worse

Black Hat via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course examines HTTP/2 implementation flaws and RFC ambiguities that enable request-desynchronization and request-smuggling attacks. It covers exploitation consequences, tooling limitations, and defensive recommendations for architects, vendors, and developers.

Syllabus

Intro
Outline
Request Smuggling via HTTP/2 downgrades
H2.TE Desync: URL token hijack
H2.TE Desync: Header hijack
H2.X via Request Splitting - Resp Queue Poisoning
H2.TE via request line injection
Possible attacks
No connection reuse
Tunnelling confirmation
Tunnel-vision Problem: Front-end reads Scontent-length bytes from back-end
Leaking internal headers via tunnelling
Cache poisoning via tunnelling
Ambiguous HTTP/2 requests
URL prefix injection
Header name splitting
The tooling situation Existing tooling does not work
Defence
References & further reading
Takeaways

Taught by

Black Hat

Reviews

Start your review of HTTP/2 - The Sequel is Always Worse

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.