Summary
HTTP Host Header 攻击方法论。当目标存在密码重置、缓存机制、反向代理、虚拟主机、重定向功能时使用。覆盖密码重置投毒(Host注入窃取reset token)、Web缓存投毒(Host控制缓存键)、通过Host路由SSRF、虚拟主机枚举与跨站读取、绕过技术(X-Forwarded-Host/双Host/绝…
wgpsec/aboutsecurity
npx skills add https://github.com/wgpsec/aboutsecurity
HTTP Host Header 攻击方法论。当目标存在密码重置、缓存机制、反向代理、虚拟主机、重定向功能时使用。覆盖密码重置投毒(Host注入窃取reset token)、Web缓存投毒(Host控制缓存键)、通过Host路由SSRF、虚拟主机枚举与跨站读取、绕过技术(X-Forwarded-Host/双Host/绝…
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
>- JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, ke…
3.1K installs>- HTTP Host header injection and routing abuse playbook. Use when the application trusts the H…
2.9K installs>- SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrappin…
2.9K installs>- Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-R…
2.9K installs>- HTTP/2 protocol-specific attack playbook. Use when the target supports HTTP/2 and you need t…
2.9K installs>- DNS rebinding attack playbook. Use when testing applications that trust DNS resolution for o…
2.9K installsOther skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Alternate registries and mirrors of this skill.
npx skills add yaklang/hack-skills --skill http-host-header-attacks
master