# Making desync attacks easy with TRACE

DevFeed: [Making desync attacks easy with TRACE](<https://devfeed.tech/articles/making-desync-attacks-easy-with-trace-7716.md>)

Original publisher: [Read original article](<https://portswigger.net/research/trace-desync-attack>)

Author: Martin Doyhenard

Published: 2024-03-19T14:00:00Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [apache](<https://devfeed.tech/tags/apache.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [http](<https://devfeed.tech/tags/http.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

The article presents TRACE as an exploitation technique for HTTP desync vulnerabilities, also known as HTTP request smuggling.

## Source excerpt

Have you ever found an HTTP desync vulnerability that seemed impossible to exploit due to its complicated constraints? In this blogpost we will explore a new exploitation technique that can be used to