What problem does it solve?
This Skill identifies and helps exploit host header vulnerabilities, such as SSRF, ATO, and cache poisoning, providing a comprehensive methodology for security assessments.
Core Features & Use Cases
- Host Header Injection Detection: Detects vulnerabilities in how applications handle host headers.
- Password Reset Poisoning: Identifies and mitigates password reset poisoning via host header manipulation.
- Web Cache Poisoning: Discovers and addresses issues with web cache poisoning via unkeyed host headers.
- SSRF via Host Header: Exploits SSRF through host header manipulation for internal service access.
- OAuth/OIDC Poisoning: Detects and mitigates attacks on OAuth and OIDC endpoints using host header manipulation.
- Quick Start: Automatically trigger relevant skills based on the description of the target environment.
Quick Start
Run the skill by describing the target in plain English, such as "Test the host header injection in acme.com".