Skip to content

HTTP & Protocol Attacks

These attacks exploit ambiguity or discrepancy in how HTTP is parsed, routed, cached, or forwarded — not application logic. The target is the gap between what the developer assumes the server does and what the actual wire behaviour is.

Topics in this section

Doc The gap exploited
HTTP Request Smuggling Front-end and back-end disagree on where one request ends and the next begins
HTTP Host Header Attacks Application trusts the Host header for routing, password-reset links, or cache keys
Web Cache Poisoning Unkeyed input taints a cached response served to all users
Web Cache Deception Path confusion tricks the cache into storing a private response as public
GraphQL Introspection exposure, batching abuse, field-level authz gaps, IDOR via node IDs
API Security OWASP API Top 10 — excessive data exposure, broken object-level authz, mass assignment
Webhooks HMAC replay, SSRF via callback URL, at-least-once delivery and receiver idempotency

Interview anchor

Request smuggling and cache poisoning are James Kettle research areas — interviewers who follow PortSwigger research ask about them at depth. Knowing the CL.TE/TE.CL/HTTP2-downgrade distinction and the unkeyed-input concept in cache poisoning puts you in the top tier for these topics.