HTTP Host header attacks
GET /example HTTP/1.1Host: vulnerable-website.com:bad-stuff-hereGET /example HTTP/1.1Host: notvulnerable-website.comGET /example HTTP/1.1Host: hacked-subdomain.vulnerable-website.comGET /example HTTP/1.1Host: vulnerable-website.comHost: bad-stuff-hereGET https://vulnerable-website.com/ HTTP/1.1Host: bad-stuff-hereGET /example HTTP/1.1 Host: bad-stuff-hereHost: vulnerable-website.com
GET /example HTTP/1.1Host: vulnerable-website.comX-Forwarded-Host: bad-stuff-hereX-HostX-Forwarded-ServerX-HTTP-Host-OverrideForwarded
How to exploit the HTTP Host header
Last updated