LogoClawIndex
CasesSkillsAbout
LogoClawIndex

http-host-header-attacks - HTTP Host Header Attacks — Injection & Routing Abuse

Covers HTTP Host header injection and routing abuse for password reset poisoning, cache poisoning, SSRF, and virtual host bypass.

Tags

Updated: 2026-09-24

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Identify Host header attack surface
  • Test password reset poisoning
  • Perform web cache poisoning
  • Route SSRF via Host header
  • Enumerate virtual host bypasses
  • Bypass Host header validation
  • Analyze framework Host behavior
  • Execute connection state Host attacks

Inputs

  • Target URL or IP address
  • HTTP request headers
  • Virtual host wordlists
  • External collaborator endpoint

Outputs

  • Poisoned password reset links
  • Poisoned web cache responses
  • Discovered virtual hosts
  • Internal network HTTP responses
  • Validation bypass test results

Requirements

  • HTTP client or intercepting proxy
  • Burp Collaborator or listener service
  • ffuf web fuzzer tool

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
http-host-header
web-security
ssrf
cache-poisoning
password-reset-poisoning
vhost-bypass
Identify Host header attack surface
Test password reset poisoning
Perform web cache poisoning
Route SSRF via Host header
Target URL or IP address
HTTP request headers
Virtual host wordlists
Poisoned password reset links
Poisoned web cache responses
Discovered virtual hosts