Skip to content

xskullboyx/X-Forwarded-Host-injector-v1

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 

Repository files navigation

X-Forwarded-Host-injector-v1

X-Forwarded-Host-injector-v1 is simple bash script for find dynamic X-Forwarded-Host-injection is possible or not on set of domains. this tool based on hackerone report https://hackerone.com/reports/737315 .

What this tool doing?

*) tool use curl to send post request to server with X-Forwarded-For header set to evil.com *) check our injected header value is reflected in server response or not

Usage:


  1. list out all subdomain to text file "subdomains.txt"
  2. run bash X-Forwarded-Host-injector-v1.sh

About

bug bounty tool - X-Forwarded-Host-injector-v1

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages