Host Header Poisoning
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
It's dangerous to rely on the value supplied in the Host header of an HTTP request.
- Prevalence
- Rare
- Exploitability
- Easy
- Impact
- Harmful
What is host header poisoning?
Host header poisoning is a spoofing attack in which an attacker sends an HTTP request with a forged Host header to an application that trusts it when generating links. The application then builds URLs pointing to the attacker's domain, which can poison password reset emails and web caches, and direct users to a malicious site.
What you'll learn
- Why a web server needs to know its own domain to build absolute URLs
- How a forged Host header poisons password reset emails
- How to take the domain from server-side configuration instead
This lesson includes
-
Host Header Poisoning lab
See why a web server has to be told its own domain, and what happens when it trusts the Host header for that. An attacker requests a password reset for a victim with a forged Host value, and the reset email sends the victim to the attacker's site.
-
How to prevent Host Header Poisoning
The prevention guide covers two approaches:
- Use Relative URLs Wherever Possible
- Take the Domain Name for Absolute URLs from Server-Side Configuration
-
Host Header Poisoning quiz
Three questions. Passing marks the lesson complete.
Sources
- What is a Host Header Attack? Acunetix
- HTTP Host Header Attacks PortSwigger
Related lessons
Browse all 45 lessons
Open Redirects
Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.
Password Mismanagement
Safe treatment of passwords is essential to a secure authentication system - yet many websites get this wrong.
Email Spoofing
Email spoofing is the sending of email messages with a forged "from" address.
Server-Side Request Forgery
An attacker can use SSRF vulnerabilities to probe your internal network.