http-host-header-attacks
CommunityExploit Host header routing and poisoning safely
Education & Research#penetration testing#ssrf#bypass techniques#virtual host#cache poisoning#host header#routing abuse
AuthorDorianGallo
Version1.0.0
Installs0
System Documentation
What problem does it solve?
It helps you identify and test when an application trusts the HTTP Host header for URL generation, routing, cache behavior, or access-control decisions, which can lead to password reset poisoning, web cache poisoning, SSRF via routing, and virtual host bypass.
Core Features & Use Cases
- Password reset poisoning: Inject an attacker-controlled Host so generated reset links point off-domain and capture tokens.
- Web cache poisoning via Host: Determine whether responses (and embedded links/scripts) reflect Host while cache keys exclude it.
- SSRF via Host routing: Check reverse proxies/load balancers that route backend services based on Host.
- Virtual host bypass & enumeration: Brute-force and probe alternate vhosts using Host values like localhost, admin, staging, and internal.
- Bypass techniques for Host validation: Evaluate common normalization mismatches such as X-Forwarded-Host/Forwarded, absolute-URI request lines, double-Host, ports/credentials parsing, trailing dots, whitespace/tab injection, and connection-state keep-alive edge cases.
- Framework-specific verification: Focus on how PHP/Django/Rails/Node derive host information and which middleware/proxy settings change behavior.
Quick Start
Ask the model to produce a Host-header test plan for a target login/reset flow, including payload candidates to validate password reset poisoning, cache-link reflection, and vhost/SSRF routing impact.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: http-host-header-attacks Download link: https://github.com/DorianGallo/hack-skills-local/archive/main.zip#http-host-header-attacks Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.