Host Header
Common Headers for Host Header Injection Attack:-
Host:
X-Host:
X-Forwarded-For:
X-Forwarder- Host:
X-Forwarder- Server:
Forwarded:
X-HTTP-Host- Override:
X-Forwarded-Proto headers:
Typical Host Header Injection Bypass: POST /endpoint/ HTTP 1.1 Host: http://evil.com Response: 403, 404 Bypass: POST /https://endpoint/ HTTP 1.1 Host: http://evil.com Response: 200, 302 Give it a try!!
Last updated