# How to join the desync endgame: Practical tips from pentester Tom Stacey

DevFeed: [How to join the desync endgame: Practical tips from pentester Tom Stacey](<https://devfeed.tech/articles/how-to-join-the-desync-endgame-practical-tips-from-pentester-tom-stacey-7724.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/how-to-join-the-desync-endgame-practical-tips-from-pentester-tom-stacey>)

Author: Andrzej Matykiewicz

Published: 2025-09-18T15:51:39Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [guest-post](<https://devfeed.tech/tags/guest-post.md>), [http](<https://devfeed.tech/tags/http.md>), [research](<https://devfeed.tech/tags/research.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

This guest post presents practical guidance for joining research into HTTP/1.1 desynchronization vulnerabilities. It discusses HTTP Request Smuggling, two novel desync vulnerability classes, their impact on major CDNs, bug bounty opportunities, and a newer scanning technique intended to identify request-boundary problems.

## Source excerpt

Note: This is a guest post by pentester and researcher, Tom Stacey (@t0xodile). You'd think that after almost 21 years since its initial public discovery, HTTP Request Smuggling would be barely exploi