hunting-host-header-and-url-parsing-trust - Hunt host header and URL parsing trust vulnerabilities
Audit trust in Host/forwarded headers and URL parser differentials across links, cache keys, routers, and allowlists.
Tags
Updated: 2026-09-23Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Establish origin of request host
- Map host and URL consumers
- Separate header trust from parser differentials
- Evaluate consumer vulnerability impact
- Verify defensive validation controls
- Confirm vulnerabilities with crafted requests
Inputs
- HTTP requests with Host headers
- Application URL parser implementations
- Configured base URLs and allowlists
- Isolated test environment
Outputs
- Poisoned links in outbound messages
- Reflected hosts in cached responses
- Routing logs to internal vhosts
- Vulnerability audit findings or kill reasons
Requirements
- Authorization for target system assessment
- Non-production isolated infrastructure
- Control over a benign domain
