====================================================================================================
ENHANCED CLOUDFLARE DESYNC SCANNER REPORT
====================================================================================================
Target: gov.ex.uk-dwpdaz.icu
Scan started: 2025-10-21 18:39:44.801101
Report file: reports/desync_scan_gov_uk-dwpdaz_icu_20251021_183944.txt
====================================================================================================

SCAN METHODOLOGY:
--------------------------------------------------
1. HTTP Request Smuggling (CL.TE, TE.CL)
2. Header Injection & Desync Attacks
3. Cache Poisoning Techniques
4. HTTP/2 Desync Attacks
5. Parameter Pollution Attacks
6. Advanced Payload Analysis

====================================================================================================

[18:39:44] [INFO] Enhanced report file initialized: reports/desync_scan_gov_uk-dwpdaz_icu_20251021_183944.txt
[18:39:44] [INFO] Starting ENHANCED comprehensive desync scan against gov.uk-dwpdaz.icu
[18:39:44] [INFO] This version provides detailed vulnerability analysis and exploitation guidance...
[18:39:44] [INFO] 
============================================================
[18:39:44] [INFO] RUNNING ENHANCED: HTTP Request Smuggling
[18:39:44] [INFO] ============================================================
[18:39:44] [INFO] Starting Enhanced HTTP Request Smuggling tests...
[18:39:44] [INFO] Generating enhanced HTTP request smuggling payloads...
[18:39:44] [INFO] Testing CL.TE Smuggling - Basic...
[18:39:45] [INFO] Testing CL.TE Smuggling - Short...
[18:39:45] [INFO] Testing TE.CL Smuggling - Basic...
[18:39:45] [INFO] Testing TE.CL Smuggling - Short...
[18:39:46] [INFO] HTTP Request Smuggling found 0 potential vulnerabilities
[18:39:46] [INFO] 
============================================================
[18:39:46] [INFO] RUNNING ENHANCED: Header Injection Desync
[18:39:46] [INFO] ============================================================
[18:39:46] [INFO] Starting Enhanced Header Desync tests...
[18:39:46] [INFO] Generating detailed desync header payloads...
[18:39:46] [INFO] Testing Header_Desync_Content-Length_Desync: Conflicting content length headers
[18:39:46] [ERROR] Error in Header_Desync_Content-Length_Desync: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: / (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208ba5010>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:46] [INFO] Testing Header_Desync_Transfer-Encoding_Conflict: Mixed Transfer-Encoding and Content-Length
[18:39:46] [ERROR] Error in Header_Desync_Transfer-Encoding_Conflict: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: / (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208bb4b90>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:46] [INFO] Testing Header_Desync_Host_Header_Injection: Multiple host header values
[18:39:46] [ERROR] Error in Header_Desync_Host_Header_Injection: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: / (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208bb56d0>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:46] [INFO] Testing Header_Desync_Protocol_Confusion: Conflicting protocol indicators
[18:39:46] [ERROR] Error in Header_Desync_Protocol_Confusion: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: / (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208bb5bd0>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:46] [INFO] Testing Header_Desync_IP_Spoofing_Headers: Multiple IP address headers
[18:39:47] [ERROR] Error in Header_Desync_IP_Spoofing_Headers: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: / (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208bb60d0>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:47] [INFO] Testing Header_Desync_Method_Override_Attack: Conflicting method override headers
[18:39:47] [ERROR] Error in Header_Desync_Method_Override_Attack: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: / (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208bb65d0>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:47] [INFO] Testing Header_Desync_URL_Rewrite_Attack: Multiple URL rewrite headers
[18:39:47] [ERROR] Error in Header_Desync_URL_Rewrite_Attack: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: / (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208bb6ad0>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:47] [INFO] Header Injection Desync found 0 potential vulnerabilities
[18:39:47] [INFO] 
============================================================
[18:39:47] [INFO] RUNNING ENHANCED: Parameter Pollution
[18:39:47] [INFO] ============================================================
[18:39:47] [INFO] Starting Enhanced Parameter Pollution tests...
[18:39:47] [INFO] Testing Param_Pollution_Duplicate_Parameters: Multiple parameters with same name
[18:39:47] [ERROR] Error in Param_Pollution_Duplicate_Parameters: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: /?username=admin&username=user (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208bb6fd0>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:47] [INFO] Testing Param_Pollution_Array_Parameters: Array-style parameters
[18:39:47] [ERROR] Error in Param_Pollution_Array_Parameters: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: /?id%5B%5D=1&id%5B%5D=2 (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208d0fc50>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:47] [INFO] Testing Param_Pollution_Mixed_Parameter_Formats: Mixed standard and object notation
[18:39:47] [ERROR] Error in Param_Pollution_Mixed_Parameter_Formats: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: /?user=test&user%5Bname%5D=admin (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208d0f610>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:47] [INFO] Testing Param_Pollution_CRLF_Injection_in_Parameters: CRLF injection attempt in parameter value
[18:39:47] [ERROR] Error in Param_Pollution_CRLF_Injection_in_Parameters: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: /?search=test%0D%0AInjection%3A+header (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208d0fd90>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:47] [INFO] Testing Param_Pollution_Parameter_in_Parameter: Nested parameter syntax
[18:39:48] [ERROR] Error in Param_Pollution_Parameter_in_Parameter: HTTPSConnectionPool(host='gov.uk-dwpdaz.icu', port=443): Max retries exceeded with url: /?query=test%26user%3Dadmin (Caused by NameResolutionError("<urllib3.connection.HTTPSConnection object at 0x7f8208d0ee90>: Failed to resolve 'gov.uk-dwpdaz.icu' ([Errno -2] Name or service not known)"))
[18:39:48] [INFO] Parameter Pollution found 0 potential vulnerabilities
