Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Not detecting H2.CL #48

Open
intrd opened this issue Oct 29, 2021 · 1 comment
Open

Not detecting H2.CL #48

intrd opened this issue Oct 29, 2021 · 1 comment

Comments

@intrd
Copy link

intrd commented Oct 29, 2021

Hey guys, I used the req. smuggler probes to solve all the new labs, including the tunnel probes it was very helpful, but looks like its not working w/ HTTP/2 CL.

  • The main HTTP/2 probe always issues as HTTP/2 TE, also in the "LAB: H2.CL request smuggling".
  • The Tunnel probe CL only do 4 requests and stop, i've tried to use it in many cases and it didn't work.
  • The Tunnel probe TE works perfectly.

So I ended up solving the CL lab as TE as well, it confused me. Also noticed that almost of them has multiple solutions (CL and TE). I will not detail here because it will give spoiler to some ppl.

This is not a problem for this case, because its solvable as TE, but apparently it is really not detecting H2.CL in any way.

..btw, thank you for this amazing extension.

@albinowax
Copy link
Collaborator

Thanks for the heads up about the multiple solutions, we'll definitely make sure that doesn't happen in any H/2 related exam questions :)

Yeah I had some code to detect H2.CL but it caused too many false positives, and as H2.CL is really rare I left it out. We've included a lab on that primarily because it's good from a learning perspective. I'll leave this ticket open in case a good detection method turns up.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants