Malformed requests
Someone tries to send a request no ordinary browser would send.
What it is
Requests that break the rules of how browsers and servers talk: conflicting lengths, forbidden characters, headers smuggled inside other headers.
- Two different lengths for the same request (request smuggling)
- A hidden character that ends the address early
- A method your site never uses
Why it matters
A request built this way is usually a tool probing for a server that gets confused, so that one visitor's request can be passed off as another's.
When it stops a real visitor
This is most often an app or a script, not a person in a browser. If it is a tool you run yourself, mark the request as real and it will be let through.
What you will see most
- The request used a method the site does not accept.
- Browsers fetch pages with GET and send forms with POST. This request used a different method, such as PUT or DELETE.
- The request contained a hidden null character.
- A character that never appears in ordinary text, used to cut an address or a file name short.
- The request asked for the site by number, not by name.
- The request was addressed to the server's numeric address. People use your site's name; programs sweeping the internet use numbers.
- The request sent a kind of content the site does not accept.
- The request said its body was a type that websites do not normally receive.
- The request carried a header that is not allowed.
- The request included a header that browsers do not send and that has been used to confuse servers.
- The request tried to smuggle a second request inside the first.
- The request was built so that a server reading it carelessly would see two requests, the second one hidden from any check.
All 56 rules in this kind, as the rule set names them
For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.
- 911100Method is not allowed by policy
- 920100Invalid HTTP Request Line
- 920120Attempted multipart/form-data bypass
- 920160Content-Length HTTP header is not numeric
- 920170GET or HEAD Request with Body Content
- 920171GET or HEAD Request with Transfer-Encoding
- 920180POST without Content-Length and Transfer-Encoding headers
- 920181Content-Length and Transfer-Encoding headers present
- 920190Range: Invalid Last Byte Value
- 920210Multiple/Conflicting Connection Header Data Found
- 920250UTF8 Encoding Abuse Attack Attempt
- 920260Unicode Full/Half Width Abuse Attack Attempt
- 920270Invalid character in request (null character)
- 920280Request Missing a Host Header
- 920290Empty Host Header
- 920310Request Has an Empty Accept Header
- 920311Request Has an Empty Accept Header
- 920330Empty User Agent Header
- 920340Content-Type header missing from request with non-zero Content-Length
- 920350Host header is a numeric IP address
- 920360Argument name too long
- 920370Argument value too long
- 920380Too many arguments in request
- 920390Total arguments size exceeded
- 920400Uploaded file size too large
- 920410Total uploaded files size too large
- 920420Request content type is not allowed by policy
- 920430HTTP protocol version is not allowed by policy
- 920440URL file extension is restricted by policy
- 920450HTTP header is restricted by policy
- 920470Illegal Content-Type header
- 920480Request content type charset is not allowed by policy
- 920500Attempt to access a backup or working file
- 920520Accept-Encoding header exceeded sensible length
- 920530Multiple charsets detected in content type header
- 920540Possible Unicode character bypass detected
- 920600Illegal Accept header: charset parameter
- 920610Raw (unencoded) fragment in request URI
- 920620Multiple Content-Type Request Headers
- 920640Content-Type header missing from request with body
- 920660Obsolete Request-Range header detected
- 921110HTTP Request Smuggling Attack
- 921120HTTP Response Splitting Attack
- 921130HTTP Response Splitting Attack
- 921140HTTP Header Injection Attack via headers
- 921150HTTP Header Injection Attack via payload (CR/LF detected)
- 921160HTTP Header Injection Attack via payload (CR/LF and header-name detected)
- 921190HTTP Splitting (CR/LF in request filename detected)
- 921200LDAP Injection Attack
- 921240mod_proxy attack attempt detected
- 921250Old Cookies V1 usage attempt detected
- 921421Content-Type header: Dangerous content type outside the mime type declaration
- 922100Multipart content type global _charset_ definition is not allowed by policy
- 922110Illegal MIME Multipart Header content-type: charset parameter
- 922120Content-Transfer-Encoding was deprecated by rfc7578 in 2015 and should not be used
- 922130Multipart header contains characters outside of valid range