LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

http-host-header-attacks

HTTP Host header injection and routing abuse playbook. Use when the application trusts the Host header for generating URLs, routing requests, or access control — enabling password reset poisoning, web cache poisoning, SSRF via routing, and virtual host bypass.

1,297stars177forksUpdated 7/7/2026
Security#security#http#penetration-testing#vulnerability-testing#web-security

Security Assessment

Low Risk(70/100)

Detected risks:

Secret Exposure([SKILL.md] token=)
Security Score70/100

About http-host-header-attacks

A security-testing playbook for probing how web applications and infrastructure trust the HTTP Host header. Because the Host value is used to generate URLs, route requests through reverse proxies, form cache keys, and make access-control decisions, an attacker who can inject or spoof it can redirect password-reset links, poison shared caches, reach internal services, or expose hidden virtual hosts. The material catalogs each of these attack surfaces and maps the Host usage to its corresponding exploitation outcome.

The centerpiece techniques include password reset poisoning (swapping the Host so the emailed reset link points to an attacker-controlled domain that captures the token), web cache poisoning when the cache key omits the Host header, SSRF through Host-based backend routing on Nginx, Apache, Kubernetes ingress, or cloud load balancers, and virtual-host discovery to reach admin or staging sites that are not in public DNS. Discovery guidance covers brute-forcing vhost names and comparing response sizes.

A large section addresses bypasses for servers that validate the Host. It documents override headers such as X-Forwarded-Host, X-Host, X-Original-URL, and RFC 7239 Forwarded that many frameworks trust ahead of the real Host, plus absolute-URI request lines, duplicate Host headers, credential and port tricks, trailing-dot FQDN mismatches, whitespace injection, and enclosed values. Framework-specific notes explain how PHP, Django, Rails, and Node/Express each read the Host and where their defaults leave gaps, and a final section introduces connection-state attacks that abuse HTTP keep-alive after an initial valid request. Intended for authorized penetration testing and security review, it emphasizes verification signals — for example checking an out-of-band collaborator for the leaked reset token — so testers can confirm rather than assume impact.

FAQ

What kind of vulnerability does this skill target?

Host header injection and routing abuse — cases where an application trusts the HTTP Host header for URL generation, request routing, cache keying, or access control.

What is password reset poisoning?

An attack where the tester changes the Host header on a reset request so the server builds the reset link with an attacker domain; when the victim clicks it, the secret token is sent to the attacker. It is described as the most common and impactful Host header attack.

How can Host validation be bypassed?

The playbook lists override headers (X-Forwarded-Host, X-Host, X-Original-URL, Forwarded), absolute-URI request lines, double Host headers, port and credential tricks, trailing dots, whitespace injection, and quoted or bracketed values.

Which frameworks are covered for Host-handling quirks?

PHP, Django, Rails, and Node/Express, with notes such as Django's USE_X_FORWARDED_HOST bypassing ALLOWED_HOSTS and Express having no built-in host validation.

How do you confirm a successful reset-poisoning or cache-poisoning test?

For reset poisoning, check an out-of-band collaborator (e.g., Burp Collaborator) for the incoming request carrying the token; for cache poisoning, send two requests with different Host values and see whether the second returns the first's Host.

Install http-host-header-attacks

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

yaklang/hack-skills

Related Skills

ccf-idea-reviewer

2,958

ccf-integrity-auditor

2,958

finance-sentiment

3,382

ccf-humanization

2,958