Node Express && HTTP Desync Attacks, request smuggling

Viewed 484
1 Answers

NodeJS applications are supposed to return '400' (a bad request) when dealing with both 'Transfer-Encoding' & 'Content-Length' in the same http request. This is good way to minimize the threat, but nothing is bullet proof.

Specification says that when server is prompt with both headers, that it should ignore 'Content-Length' and proceed with 'Transfer-Encoding', but this is not often the case, nor it is a good thing to do.

From what I can see in the wild, implementation can differ a lot, like a LOT. There is no the best way to deal with this problem. (One of the reasons why it is very common flaw, which can be exploited easily by chaining it with the other flaws in the system)

Related