Re: Bug: RFC 7230 Section 3.3.3 violation in httpd header parsing enables TE.CL Request Smuggling

Ben Kallus <[email protected]>
Newsgroups gmane.os.openbsd.bugs
Message-ID <CAB6pCSa3ji0jM4X02GqZ4U_bPisaLy3TJZ8zv4+0YJZqRiC+Cw@mail.gmail.com>
> Playing devils advocate here. If your request makes it through the WAF /
> reverse proxy then aren't those systems vulnerable to this and not httpd?

Yes. That's the problem with these request smuggling bugs; you often
need a bug in the middlebox *and* the origin server to exploit them,
but they only violate the security model of the middlebox. I'd say
that correctness is more important than assigning blame here, though.
Best to fix it in both places?

-Ben
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.