http-host-header-attacks - HTTP Host Header Attacks — Injection & Routing Abuse
Covers HTTP Host header injection and routing abuse for password reset poisoning, cache poisoning, SSRF, and virtual host bypass.
Tags
Updated: 2026-09-24Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Identify Host header attack surface
- Test password reset poisoning
- Perform web cache poisoning
- Route SSRF via Host header
- Enumerate virtual host bypasses
- Bypass Host header validation
- Analyze framework Host behavior
- Execute connection state Host attacks
Inputs
- Target URL or IP address
- HTTP request headers
- Virtual host wordlists
- External collaborator endpoint
Outputs
- Poisoned password reset links
- Poisoned web cache responses
- Discovered virtual hosts
- Internal network HTTP responses
- Validation bypass test results
Requirements
- HTTP client or intercepting proxy
- Burp Collaborator or listener service
- ffuf web fuzzer tool
