Host Header Injection
Host Header injection
GET /page HTTP/1.1
Host: example.comTesting Steps:
GET /page HTTP/1.1
Host: malicious-domain.comGET /page HTTP/1.1
Host: example.com:bad-portDuplicate Host
GET /page HTTP/1.1
Host: example.com:bad-port
Host: t.example.com:bad-portAbsolute URL:
Common Attack Vectors
Mitigation and Prevention
Last updated