Web Host Header

Host header injection — abuse a trusted Host/X-Forwarded-Host to poison password-reset links, routing, and caches. Load when the app builds absolute URLs from the request host, on password-reset flows, or behind a proxy/CDN. Signals: reset emails with links, X-Forwarded-Host reflected, virtual hosting, cache in front.

NoorQureshi ce44881 2.2 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-host-header commit ce4488197e

Frequently asked questions

npx skillmds@latest add noorqureshi/web-host-header