FINDING · DEFENSE

HTTP request smuggling (HRS) vectors that exploit CL/TE header parsing divergence between a censor-as-middlebox and a destination web server can circumvent HTTP censorship in China, Iran, and Russia. Of 4,488 test vectors derived from prior HRS research, 2,015 (44.9%) were accepted by at least one web server; CL*/TE vectors achieved a 99.0% web-server acceptance rate while TE/CL* vectors achieved 0%.

From 2024-niere-http-smugglingTurning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling · §3, §5.1, Table 1 · 2024 · FOCI 2024 (Free and Open Communications on the Internet)

Implications

Tags

censors
cnirru
techniques
dpikeyword-filteringmiddlebox-interference
defenses
meta-resistancegeneva

Extracted by claude-sonnet-4-6 — review before relying.