The Desync Endgame: Everything Looks Secure Until It Isn’t

▶ Watch (0:46)

Kettle opened with a Cloudflare case study. A bug hunter found a desync that hijacked users on random websites, including banks. Kettle initially blamed a Cloudflare-to-Heroku desync. He was wrong. The attacker had forgotten a cache buster. That mistake caused a desync inside Cloudflare’s own infrastructure, enabling persistent compromise of almost every website using Cloudflare — 24 million sites. The industry patched detection tools and regex filters for six years. They did not patch the underlying vulnerability.

Five Lies About HTTP/1.1 and a New Detection Toolkit

▶ Watch (7:32)

Kettle listed five false beliefs about HTTP/1.1, all exploited in the talk. Combined, they force a proxy to maintain state just to read the correct number of bytes from a TCP socket. He released HTTP Request Smuggler v3, an open-source Burp extension. It uses a broad range of techniques to classify parser discrepancies between front-end and back-end servers. One scan found a hidden-visible discrepancy on a bank’s web VPN using a malformed duplicate Host header.

Zero-CL Desyncs: The “Impossible” Attack

▶ Watch (14:58)

Zero-CL desyncs were considered impossible because the back-end times out waiting for a body. Kettle found the solution in IIS. Requesting a Windows reserved name like /con triggers an early response before the body arrives, escaping the deadlock. He chained this with a double desync to weaponize a victim’s request. The technique required sending a few hundred requests per second due to a race condition. A Web Security Academy lab is now available to practice it.

The Expect Header: A New Attack Surface

▶ Watch (21:59)

The Expect header breaks request sending into a two-part process. No browsers support it, but virtually all servers do. Kettle found that combining Expect with a HEAD request caused servers to deadlock. On multiple web servers, Expect leaked memory including secret keys. On Netlify’s CDN, it revealed internal headers on every site. A team of bounty hunters and Kettle used Expect to achieve zero-CL desyncs on T-Mobile ($12,000) and GitLab ($7,000), and CL.0 desyncs on Netlify’s entire CDN.

Akamai, LastPass, and $350,000 in Bounties

▶ Watch (28:02)

The final attack gave full control over orth.lastpass.com and worked on a large number of Akamai customers. Kettle faced a choice: report to each company individually or report to Akamai. He let the bounty hunters report it without him. They earned over $200,000. Kettle later received a $9,000 bounty from Akamai directly. Total bounties from the research exceeded $350,000. The fix took Akamai over 65 days.

Q&A

What is the single most impactful thing a company can do to protect against desync attacks? Enable upstream HTTP/2 on the front-end server and ensure the origin supports it. ▶ 32:21

Does the research apply to HTTP/3? HTTP/2 and HTTP/3 do not have the fatal request-isolation flaw, so implementation bugs are much lower impact. ▶ 32:02

Why don’t major CDNs like CloudFront support upstream HTTP/2? They cite legacy client compatibility, but Kettle argued that is not a valid reason to leave millions of sites vulnerable. ▶ 33:00

Notable Quotes

This is the desync endgame. Everything looks secure, but if you do one thing slightly wrong, you can end up hacking 24 million websites. James “albinowax” Kettle · ▶ 6:33

This is HTTP1. It’s the foundation of the web and it’s composed of landmines that routinely expose millions of websites and we’ve spent 6 years demonstrating that we’re not able to fix it. It needs to die. James “albinowax” Kettle · ▶ 8:11

Basically, when you use a cloud proxy, you’re importing other people’s technical debt into your own infrastructure. James “albinowax” Kettle · ▶ 14:30

Key Takeaways

  • HTTP/1.1 desync attacks are not patched; only detection methods are.
  • Zero-CL desyncs are possible using early-response gadgets like IIS’s /con.
  • The Expect header is a rich new source of CL.0 and zero-CL desyncs.
  • Upstream HTTP/2 is the only reliable fix; downgrading makes the threat worse.

About the Speaker(s)

James “albinowax” Kettle is the Director of Research at PortSwigger, the makers of Burp Suite. He pioneered HTTP Desync Attacks, web cache poisoning, the single-packet attack, server-side template injection, and password reset poisoning. He introduced OAST via Burp Collaborator, bulk parameter discovery via Param Miner, billion-request attacks with Turbo Intruder, and human-style scanning with Backslash Powered Scanner. He also designed many of the topics and labs in the Web Security Academy.