HTTP Host header injection and routing abuse playbook. Use when the application trusts the Host header for generating URLs, routing requests, or access control — enabling password reset poisoning, web cache poisoning, SSRF via routing, and virtual host bypass.
Detected risks:
A security-testing playbook for probing how web applications and infrastructure trust the HTTP Host header. Because the Host value is used to generate URLs, route requests through reverse proxies, form cache keys, and make access-control decisions, an attacker who can inject or spoof it can redirect password-reset links, poison shared caches, reach internal services, or expose hidden virtual hosts. The material catalogs each of these attack surfaces and maps the Host usage to its corresponding exploitation outcome.
The centerpiece techniques include password reset poisoning (swapping the Host so the emailed reset link points to an attacker-controlled domain that captures the token), web cache poisoning when the cache key omits the Host header, SSRF through Host-based backend routing on Nginx, Apache, Kubernetes ingress, or cloud load balancers, and virtual-host discovery to reach admin or staging sites that are not in public DNS. Discovery guidance covers brute-forcing vhost names and comparing response sizes.
A large section addresses bypasses for servers that validate the Host. It documents override headers such as X-Forwarded-Host, X-Host, X-Original-URL, and RFC 7239 Forwarded that many frameworks trust ahead of the real Host, plus absolute-URI request lines, duplicate Host headers, credential and port tricks, trailing-dot FQDN mismatches, whitespace injection, and enclosed values. Framework-specific notes explain how PHP, Django, Rails, and Node/Express each read the Host and where their defaults leave gaps, and a final section introduces connection-state attacks that abuse HTTP keep-alive after an initial valid request. Intended for authorized penetration testing and security review, it emphasizes verification signals — for example checking an out-of-band collaborator for the leaked reset token — so testers can confirm rather than assume impact.
Host header injection and routing abuse — cases where an application trusts the HTTP Host header for URL generation, request routing, cache keying, or access control.
An attack where the tester changes the Host header on a reset request so the server builds the reset link with an attacker domain; when the victim clicks it, the secret token is sent to the attacker. It is described as the most common and impactful Host header attack.
The playbook lists override headers (X-Forwarded-Host, X-Host, X-Original-URL, Forwarded), absolute-URI request lines, double Host headers, port and credential tricks, trailing dots, whitespace injection, and quoted or bracketed values.
PHP, Django, Rails, and Node/Express, with notes such as Django's USE_X_FORWARDED_HOST bypassing ALLOWED_HOSTS and Express having no built-in host validation.
For reset poisoning, check an out-of-band collaborator (e.g., Burp Collaborator) for the incoming request carrying the token; for cache poisoning, send two requests with different Host values and see whether the second returns the first's Host.
Quick Setup:
.claude/skills/Repository
yaklang/hack-skills