Skip to content
This repository was archived by the owner on Mar 14, 2020. It is now read-only.

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

VulnerableGunicorn

This is a simple application and infrastructure to test HTTP Desync Attacks against Gunicorn+Flask running in ECS behind an AWS ALB.

The whole process is detailed in my blog post.

Deploy

  1. In the infra folder, terraform apply
  2. Change the AWS account ID in the deploy.sh script
  3. ./deploy.sh

Thanks

The application is largely inspired by code used in the blog post HAProxy HTTP request smuggling.

About

Test Gunicorn + ECS HTTP Desync Attacks

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Used by

Contributors

Languages