Skip to content
This repository has been archived by the owner on Mar 14, 2020. It is now read-only.
/ VulnerableGunicorn Public archive

Test Gunicorn + ECS HTTP Desync Attacks

License

Notifications You must be signed in to change notification settings

Sytten/VulnerableGunicorn

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

VulnerableGunicorn

This is a simple application and infrastructure to test HTTP Desync Attacks against Gunicorn+Flask running in ECS behind an AWS ALB.

The whole process is detailed in my blog post.

Deploy

  1. In the infra folder, terraform apply
  2. Change the AWS account ID in the deploy.sh script
  3. ./deploy.sh

Thanks

The application is largely inspired by code used in the blog post HAProxy HTTP request smuggling.

About

Test Gunicorn + ECS HTTP Desync Attacks

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published