GithubHelp home page GithubHelp logo

hktalent / http-smuggling-lab Goto Github PK

View Code? Open in Web Editor NEW

This project forked from zeddyu/http-smuggling-lab

0.0 1.0 0.0 563 KB

Use HTTP Smuggling Lab to learn HTTP Smuggling.

Shell 12.87% Python 13.10% PHP 4.49% VCL 4.42% HTML 7.78% Dockerfile 57.35%

http-smuggling-lab's Introduction

HTTP-Smuggling-Lab

HTTP-Smuggling-Lab is a lab for learning about the http request smuggling.

Installation

use docker-compose to build the lab in each directory.

Usage

Read the README.md in details in each directory.

  • In Lab1, we will chain some Reverse Proxy relations, Nginx will be the final backend, HaProxy the front load balancer, and between Nginx and HaProxy we will go through ATS6 or ATS7 based on the domain name used (dummy-host7.example.com for ATS7 and dummy-host6.example.com for ATS6).
  • Lab2 uses ATS as front server and uses LAMP and LNMP as backend servers.
  • Jetty is jetty v9.4.9. You will get more information in Jetty-README.
  • Websocket Lab is about the websocket http smuggling. You will get more information in Websocket-README.
  • HTTP/2 cleartext request smuggling please use this: h2csmuggler

You can learn more in Help you understand HTTP Smuggling in one article or the chinese version 一篇文章带你读懂 HTTP Smuggling 攻击.

Contributing

Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.

Please make sure to update tests as appropriate.

Thanks to @regilero and mengchen@Knownsec 404 Team.

License

MIT

http-smuggling-lab's People

Contributors

zeddyu avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.