Testing For Crlf Injection

Testing web applications for CRLF (Carriage Return / Line Feed) injection where unsanitized %0d%0a sequences in user input let an attacker inject HTTP headers, split responses, poison caches, plant cookies, or pivot to XSS and request smuggling. Activates when user input is reflected into response headers, Location redirects, log files, or outbound requests made by the application.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/xalgord@xalgorix/internal/tools/skills/data/web-application-security/testing-for-crlf-injection commit 08121521d7

Frequently asked questions

npx skillmds@latest add gabrielmoreira/testing-for-crlf-injection