HTTP Terminator: AI-Powered Open Source Tool Discovers Novel HTTP Request-Smuggling Techniques
James Kettle has spent four years turning HTTP request smuggling from a niche trick into a systematic research engine. The result is HTTP Terminator, an autonomous system that invents, evaluates, and weaponizes new attack techniques at scale. During a recent interview with the Dark Reading News Desk, Kettle described how the system follows four broad stages: ideation, evaluation, weaponization, and cascade. In the ideation phase, HTTP Terminator read 138 technical specifications and broke them into 15,000 fragments of inspiration. From those fragments, it generated 30,000 unique attack vectors and tested them against live targets authorized through bug bounty programmes. The system confirmed roughly 700 vulnerable targets, demonstrating real-world impact across government infrastructure, financial institutions, and widely deployed enterprise products.
But the most important finding, Kettle emphasized, is what happens when the system steps back and a human takes over. As WIRED highlighted in its coverage of the research, this is where human experience and intuition still mattered most. The system could generate more leads and pursue them faster, handling much of the repetitive work. Kettle could focus on recognizing which unusual results were worth taking further. Rather than removing the researcher from the process, HTTP Terminator gave his methodology far greater reach.
Browser-Powered Desync Attacks
Perhaps the most striking class of vulnerabilities HTTP Terminator uncovered is browser-powered desync. In this technique, the victim's web browser becomes the desync delivery platform, shifting the request smuggling frontier by exposing single-server websites and internal networks. The attack combines cross-domain requests with server flaws to poison browser connection pools, install backdoors, and release desync worms.
The research uncovered several sub-technics. Client-side desync (CSD) poisons the connection between the browser and the front-end server, enabling exploitation of single-server websites that are often spectacularly poor at HTTP parsing. A CSD attack starts with the victim visiting the attacker's website, which then makes the browser send two cross-domain requests to the vulnerable website. The first request is crafted to desync the browser's connection, and the second request triggers a harmful response, typically giving the attacker control of the victim's account.
Detection follows a methodology Kettle helped formalize: first, identify a CSD vector—a HTTP request where the server ignores the request's Content-Length and the request is triggerable in a web browser cross-domain. Confirm the vector by issuing two requests down the same connection and looking for the body of the first affecting the response to the second. Finally, replicate the behaviour inside a real browser, using Chrome developer tools to observe connection IDs and confirm the second request triggers an unexpected response.
Pause-based desync is another technique affecting Apache and Varnish, usable for both server-side and client-side desync exploits. This technique exploits servers that process requests differently when a pause is inserted between them. Kettle's team developed an early-read technique to prove vulnerability: after completing a chunked request with `0
`, attempting an early read. If the server responds during the read attempt, the front-end thinks the message is complete and must have securely interpreted it as chunked. If the read attempt hangs, the front-end is waiting for the message to finish and must be using the Content-Length, making it vulnerable.
The research also revealed an extremely effective novel desync trigger solved through black-box analysis methodology. This trigger works without header obfuscation or ambiguity—all that's needed is a server taken by surprise. Kettle reported a finding on Amazon's ALB where a vanilla HTTP/2 request without a Content-Length header caused the load balancer to add Transfer-Encoding: chunked while downgrading the request to HTTP/1.1, opening the door to request smuggling. The attack was so vanilla that a browser could issue it using fetch().
The Discovery Cascade
What emerged from the research is a clearer picture of the research process itself. HTTP Terminator's strongest results came when Kettle stepped back in at the discovery cascade: the point where one finding becomes the starting point for the next hypothesis. This is where human experience and intuition still mattered most. The system could generate more leads and pursue them faster, handling much of the repetitive work. Kettle could focus on recognizing which unusual results were worth taking further.
Kettle's work also shaped the development of Burp AT, PortSwigger's agentic AI designed for professional security testing. The research showed how much more effective an AI system becomes when it can use purpose-built security tools and apply a clear methodology, rather than trying to handle every task from first principles. It also showed that expert judgement still has an important role at the points where it adds the most value.
Real-World Impact
The scale of HTTP Terminator's results is striking. The system tested 30,000 websites where scanning was authorized through bug bounty or vulnerability disclosure programs and found roughly 700 vulnerable targets before deeper validation and research. Findings involved banks, government infrastructure, security products, and even an airport. A separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server.
The implications are clear. An autonomous system can invent new attack techniques and use them to hack live websites at scale. But the research also revealed that human experience and intuition still matter most at the discovery cascade point. The HTTP Terminator is not Burp AT—it is a research system built to test the limits of what AI can discover. But its findings are already shaping practical capabilities that security professionals can use during real security testing.
Tools and Resources
PortSwigger has made the HTTP Terminator source code and a research blueprint available as open-source proof of concept, together with a framework for other researchers who want to encode their own methods and areas of expertise. The team has also built Academy topics with live replicas of key vulnerabilities, so practitioners can practice online for free. Full source-code updates to HTTP Request Smuggler and Turbo Intruder are also available, covering every case study from the research.
Kettle's paper goes into the technical detail: how the system works, the attack techniques it uncovered, the limits he encountered, and the discoveries that emerged from the combination of autonomous research and expert input. He is also making the HTTP Terminator available as open source, together with a blueprint for other researchers who want to encode their own methods and areas of expertise.
This article is based on verified sources including the PortSwigger blog post "Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research," the Lifeboat blog post "AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache ZeroDay," and the PortSwigger research paper "Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling." The research-notes outline and sourceRefs from the existing article d16bb06b-02bb-4679-bce5-0d28c3eb2780 were followed throughout.