Vulnerable Software
Overview
Gunicorn 20.0.4 - Sec-Websocket-Key1 Bug
Vulnerability Details
Property
Value
The Bug
Why It's Exploitable
Identification
Detection Request
Testing Procedure
Expected Results
Request
Expected Path
Actual Response
TCP Stream Analysis
Reverse Proxy View
Gunicorn View (Buggy)
Exploitation - WAF Bypass
Scenario
Exploit Requests
Content-Length Calculation
Attack Flow
Server Detection
Identifying Gunicorn
Version Check
The 8-Byte Padding
Why xxxxxxxx?
xxxxxxxx?Calculation Template
Other Vulnerable Software
Known Request Smuggling CVEs
Software
CVE
Description
Research Resources
Tips & Tricks
Testing Multiple Versions
Burp Configuration
Fallback Strategy
Lab Walkthrough Summary
References
Last updated