Host Header Attacks
Possible attack vectors
Check for flawed validation
GET /example HTTP/1.1
Host: vulnerable-website.com:bad-stuff-hereGET /example HTTP/1.1
Host: hacked-subdomain.vulnerable-website.comSend ambigious requests
GET /example HTTP/1.1
Host: vulnerable-website.com
Host: bad-stuff-hereGET https://vulnerable-website.com/ HTTP/1.1
Host: bad-stuff-hereGET /example HTTP/1.1
Host: bad-stuff-here
Host: vulnerable-website.comPotential Headers to inject
Lab: Basic password reset poisoning



Lab: Web cache poisoning via ambiguous requests


Lab: Host header authentication bypass













Lab: Host validation bypass via connection state attack




Last updated