Skip to content

What it blocks

Malformed requests

Someone tries to send a request no ordinary browser would send.

What it is

Requests that break the rules of how browsers and servers talk: conflicting lengths, forbidden characters, headers smuggled inside other headers.

  • Two different lengths for the same request (request smuggling)
  • A hidden character that ends the address early
  • A method your site never uses

Why it matters

A request built this way is usually a tool probing for a server that gets confused, so that one visitor's request can be passed off as another's.

If a real visitor is ever stopped

This is most often an app or a script, not a person in a browser. If it is a tool you run yourself, mark the request as real and it will be let through.