HTTP Request Smuggling Explained (with James Kettle)

HTTP Request Smuggling Explained (with James Kettle)

Source: YouTube · NahamSec · published Aug 4, 2025 · 21:16

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

HTTP request smuggling exploits the discrepancy between front-end and back-end servers, allowing attackers to hijack sessions and poison caches without user interaction 2:15.

Key Takeaways:
• The vulnerability exists in the "gap" between proxy and backend server parsers, leading to cache poisoning and credential theft 2:15.
• James Kettle, a leading researcher in this field, is featured to explain the mechanics and detection of these bugs 0:32.
• Successful exploitation can result in full domain takeovers through a single crafted HTTP request 0:25.

Understanding these server-side parsing mismatches is critical for securing modern web architectures against sophisticated attacks.

Sources:

  • 2:15 Definition and impact of HTTP request smuggling
  • 0:32 Introduction of expert James Kettle
  • 0:25 Potential consequences including domain takeovers

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Imagine sending a request to a website and having it secretly hijack someone else's session, trigger an admin action, or even worse, bypass authentication, all without them clicking on a single thing. That is HTTP request smuggling, a vulnerability that doesn't live in the front end or the back end, but it lives in the gap between them. And when that gap gets exploited, you're looking at full cache poisoning, credential theft, and even sometimes full domain takeovers, all from a single weird looking HTTP request. And to even dig deeper, I invited James Kettle, who has done more to push this bug forward than anyone else that I know, to join me and help me break this down. So, I did an interview with him. We're going to first talk to him about how he approaches this research, what are the th…