Launch Your Cybersecurity Career in 6 Months
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This session explains why HTTP request smuggling works, how to safely detect desynchronization, and how to exploit it through case studies involving internal systems, cache poisoning, CDNs, and user compromise. It concludes with mitigation guidance and a live demonstration.
Syllabus
Introduction
The HTTP Chain
Desynchronisation
Why does it work
Detection
Case Studies
Smuggling
Backend System
Cache Poisoning
CDNs
DOM
Local Feed
PayPal
PayPal Login
Demo
How to fix
Taught by
Black Hat