request-smuggling - Test HTTP request smuggling and desynchronization
Tests request-boundary disagreements across proxies, CDNs, load balancers, origins, and browser fetch pipelines.
Tags
Updated: 2026-09-29Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Probe CL.TE differentials
- Probe TE.CL differentials
- Test TE.TE obfuscation variants
- Analyze HTTP/2 downgrade behavior
- Test client-side desynchronization
- Map parser boundary disagreements
- Use tool-assisted fuzzing
Inputs
- Target endpoint
- Proxy topology
- Origin behavior
- HTTP request variants
- Browser fetch context
Outputs
- Smuggling test probes
- Parser differential findings
- Desynchronization observations
- Request-boundary analysis
Requirements
- Authorized testing scope
- HTTP/1.1 framing knowledge
- Reverse-proxy topology familiarity
