wgpsec/aboutsecurity

http-host-header-attacks

First seen Apr 22, 2026

Installation

$ npx skills add https://github.com/wgpsec/aboutsecurity

Summary

HTTP Host Header 攻击方法论。当目标存在密码重置、缓存机制、反向代理、虚拟主机、重定向功能时使用。覆盖密码重置投毒(Host注入窃取reset token)、Web缓存投毒(Host控制缓存键)、通过Host路由SSRF、虚拟主机枚举与跨站读取、绕过技术(X-Forwarded-Host/双Host/绝…

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from wgpsec/aboutsecurity · top by installs.

npx skills add https://github.com/wgpsec/aboutsecurity

Browse all from wgpsec/aboutsecurity

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Also listed on

Alternate registries and mirrors of this skill.

Repository health

Stars 1.7K
Default branch master
Open issues 0
Status Active

History

  1. First seen on skills.sh
  2. First recorded snapshot · 16 installs