Browser HTTP Request Smuggling

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๋ธŒ๋ผ์šฐ์ € ๊ธฐ๋ฐ˜ desync(์ฆ‰, ํด๋ผ์ด์–ธํŠธ ์ธก ์š”์ฒญ ์Šค๋จธ๊ธ€๋ง)๋Š” ํ”ผํ•ด์ž์˜ ๋ธŒ๋ผ์šฐ์ €๋ฅผ ์•…์šฉํ•˜์—ฌ ์ž˜๋ชป๋œ ํ”„๋ ˆ์ž„์˜ ์š”์ฒญ์„ ๊ณต์œ  ์—ฐ๊ฒฐ์— ํ์ž‰ํ•˜์—ฌ ํ›„์† ์š”์ฒญ์ด ๋‹ค์šด์ŠคํŠธ๋ฆผ ๊ตฌ์„ฑ ์š”์†Œ์— ์˜ํ•ด ๋น„๋™๊ธฐ์ ์œผ๋กœ ๊ตฌ๋ฌธ ๋ถ„์„๋˜๋„๋ก ํ•ฉ๋‹ˆ๋‹ค. ๊ณ ์ „์ ์ธ FEโ†”BE ์Šค๋จธ๊ธ€๋ง๊ณผ ๋‹ฌ๋ฆฌ, ํŽ˜์ด๋กœ๋“œ๋Š” ๋ธŒ๋ผ์šฐ์ €๊ฐ€ ๊ต์ฐจ ์ถœ์ฒ˜๋กœ ํ•ฉ๋ฒ•์ ์œผ๋กœ ๋ณด๋‚ผ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์— ์˜ํ•ด ์ œํ•œ๋ฉ๋‹ˆ๋‹ค.

์ฃผ์š” ์ œ์•ฝ ์‚ฌํ•ญ ๋ฐ ํŒ

  • ๋ธŒ๋ผ์šฐ์ €๊ฐ€ ํƒ์ƒ‰, fetch ๋˜๋Š” ์–‘์‹ ์ œ์ถœ์„ ํ†ตํ•ด ๋ฐฉ์ถœํ•  ์ˆ˜ ์žˆ๋Š” ํ—ค๋” ๋ฐ ๊ตฌ๋ฌธ๋งŒ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค. ํ—ค๋” ๋‚œ๋…ํ™”(LWS ํŠธ๋ฆญ, ์ค‘๋ณต TE, ์ž˜๋ชป๋œ CL)๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ ์ „์†ก๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
  • ์ž…๋ ฅ์„ ๋ฐ˜์˜ํ•˜๊ฑฐ๋‚˜ ์‘๋‹ต์„ ์บ์‹œํ•˜๋Š” ์—”๋“œํฌ์ธํŠธ ๋ฐ ์ค‘๊ฐœ์ž๋ฅผ ํƒ€๊ฒŸ์œผ๋กœ ํ•˜์‹ญ์‹œ์˜ค. ์œ ์šฉํ•œ ์˜ํ–ฅ์—๋Š” ์บ์‹œ ์˜ค์—ผ, ํ”„๋ก ํŠธ ์—”๋“œ ์ฃผ์ž… ํ—ค๋” ๋ˆ„์ถœ ๋˜๋Š” ํ”„๋ก ํŠธ ์—”๋“œ ๊ฒฝ๋กœ/๋ฉ”์„œ๋“œ ์ œ์–ด ์šฐํšŒ๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.
  • ์žฌ์‚ฌ์šฉ์ด ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค: ์กฐ์ž‘๋œ ์š”์ฒญ์ด ๊ณ ๊ฐ€์น˜ ํ”ผํ•ด์ž ์š”์ฒญ๊ณผ ๋™์ผํ•œ HTTP/1.1 ๋˜๋Š” H2 ์—ฐ๊ฒฐ์„ ๊ณต์œ ํ•˜๋„๋ก ์ •๋ ฌํ•˜์‹ญ์‹œ์˜ค. ์—ฐ๊ฒฐ ์ž ๊ธˆ/์ƒํƒœ ์œ ์ง€ ๋™์ž‘์€ ์˜ํ–ฅ์„ ์ฆํญ์‹œํ‚ต๋‹ˆ๋‹ค.
  • ์‚ฌ์šฉ์ž ์ •์˜ ํ—ค๋”๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์€ ์›์‹œ ์š”์†Œ๋ฅผ ์„ ํ˜ธํ•˜์‹ญ์‹œ์˜ค: ๊ฒฝ๋กœ ํ˜ผ๋ž€, ์ฟผ๋ฆฌ ๋ฌธ์ž์—ด ์ฃผ์ž… ๋ฐ ์–‘์‹ ์ธ์ฝ”๋”ฉ๋œ POST๋ฅผ ํ†ตํ•œ ๋ณธ๋ฌธ ํ˜•์„ฑ.
  • ์žฌ์‚ฌ์šฉ ์—†์ด ์žฌํ…Œ์ŠคํŠธํ•˜๊ฑฐ๋‚˜ HTTP/2 ์ค‘์ฒฉ ์‘๋‹ต ๊ฒ€์‚ฌ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ง„์ •ํ•œ ์„œ๋ฒ„ ์ธก desync์™€ ๋‹จ์ˆœํ•œ ํŒŒ์ดํ”„๋ผ์ธ ์•„ํ‹ฐํŒฉํŠธ๋ฅผ ๊ฒ€์ฆํ•˜์‹ญ์‹œ์˜ค.

์—”๋“œ ํˆฌ ์—”๋“œ ๊ธฐ์ˆ  ๋ฐ PoC์— ๋Œ€ํ•œ ๋‚ด์šฉ์€ ๋‹ค์Œ์„ ์ฐธ์กฐํ•˜์‹ญ์‹œ์˜ค:

  • PortSwigger Research โ€“ Browserโ€‘Powered Desync Attacks: https://portswigger.net/research/browser-powered-desync-attacks
  • PortSwigger Academy โ€“ clientโ€‘side desync: https://portswigger.net/web-security/request-smuggling/browser/client-side-desync

References

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ