Abusing Hop By Hop Headers

Testing proxies, load balancers, and CDNs for improper handling of HTTP hop-by-hop headers, where an attacker uses the Connection header to designate arbitrary headers as hop-by-hop so an intermediary strips them before they reach the backend. Enables IP-based access-control bypass (X-Forwarded-For), header-stripping attacks on auth and caching, and cache poisoning. Activates when a target sits behind one or more HTTP/1.1 proxies.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/xalgord@xalgorix/internal/tools/skills/data/web-application-security/abusing-hop-by-hop-headers commit d0466d0913

Frequently asked questions

npx skillmds@latest add gabrielmoreira/abusing-hop-by-hop-headers