20–30 min Updated

Host Header Poisoning

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

It's dangerous to rely on the value supplied in the Host header of an HTTP request.

Prevalence
Rare
Exploitability
Easy
Impact
Harmful

What is host header poisoning?

Host header poisoning is a spoofing attack in which an attacker sends an HTTP request with a forged Host header to an application that trusts it when generating links. The application then builds URLs pointing to the attacker's domain, which can poison password reset emails and web caches, and direct users to a malicious site.

What you'll learn

  • Why a web server needs to know its own domain to build absolute URLs
  • How a forged Host header poisons password reset emails
  • How to take the domain from server-side configuration instead
  • Host Header Poisoning lab

    See why a web server has to be told its own domain, and what happens when it trusts the Host header for that. An attacker requests a password reset for a victim with a forged Host value, and the reset email sends the victim to the attacker's site.

  • How to prevent Host Header Poisoning

    The prevention guide covers two approaches:

    • Use Relative URLs Wherever Possible
    • Take the Domain Name for Absolute URLs from Server-Side Configuration
  • Host Header Poisoning quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Open Redirects

    Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.

  • Password Mismanagement

    Safe treatment of passwords is essential to a secure authentication system - yet many websites get this wrong.

  • Email Spoofing

    Email spoofing is the sending of email messages with a forged "from" address.

  • Server-Side Request Forgery

    An attacker can use SSRF vulnerabilities to probe your internal network.