
The Entire Internet is Broken
Source: YouTube · John Hammond · published Aug 25, 2025 · 22:18
HTTP/1.1 request smuggling remains a critical, under-addressed vulnerability with widespread real-world impact, exposing billions of websites to severe security risks despite widespread belief it’s "fixed" 2:30-3:49.
Key Takeaways:
• HTTP/1.1’s poor request isolation allows attackers to confuse front-end and back-end servers, enabling arbitrary response manipulation, including session hijacking and cache poisoning 2:30-3:49.
• Attackers can exploit subtle header changes—like a trailing space in the Host header—to trigger desync attacks, leading to unauthorized access or data exfiltration 8:30-9:03.
• A zero CL desync attack allows prefix injection, enabling full control over victim responses, including JavaScript execution or credential theft 13:00-14:45.
• James Kettle demonstrated exploitation across major CDNs (Akamai, Cloudflare), potentially compromising over 30 million websites, with over $350,000 in bounties earned 15:09-16:02.
• The only viable long-term solution is migrating upstream connections to HTTP/2, which eliminates these flaws—backwards compatibility remains a major barrier 18:42-19:11.
The research underscores that HTTP/1.1 is fundamentally broken and that awareness, not just patching, is essential to driving industry change.
Sources:
- 2:30 Explains request smuggling, its impact, and how it breaks request isolation.
- 8:30 Details desync attacks using subtle header modifications.
- 13:00 Describes zero CL desync and its use in response poisoning.
- 15:09 Shows real-world exploitation of CDNs and financial impact.
- 18:42 Outlines the proposed solution: migrating to HTTP/2.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Alrighty. Hi everyone. Hey, thanks so much for tuning in. Look, I'm super excited to finally spend some time with James Kettle, the director of research over at Portswiger, doing incredible things. Hey, working with Burpsweet, doing phenomenal research. And we did just get a chance to chat at Black Hat at Defcon, all the fun Las Vegas hacker summer camp activities. Uh, but James, it's great to be here with you, man. How you doing? How you feeling? And can you let us know what you've been up to? >> Really good, thanks. Super hyped to see how well this research has been received by the community. had an absolutely packed room at Defcon and we're already seeing posts on LinkedIn of people saying, "Oh, there might have been some zero days in that talk." Unintentional zero day. So, you immediat…