Autoplay
Autocomplete
Previous Lesson
Complete and Continue
HTTP Host Header Attacks
Introduction
Course Introduction (1:56)
Course Slides and Scripts
Getting Help
Answering Your Questions (3:11)
Join the Discord Server
Lab Environment Setup
Lab Environment Setup (7:21)
Step-by-Step Guide
HTTP Host Header Attacks - Technical Deep Dive
Agenda (1:29)
Introduction to the HTTP Host Header (2:44)
What are Host Header Vulnerabilities (4:09)
How to Find & Exploit Host Header Vulnerabilities (8:11)
How to Secure the Host Header (2:36)
Resources (0:24)
Hands-On HTTP Host Header Attacks Labs
Lab #1 Basic password reset poisoning (9:18)
Lab #2 Host header authentication bypass (6:48)
Lab #3 Web cache poisoning via ambiguous requests (19:34)
Lab #4 Routing-based SSRF (12:36)
Lab #5 SSRF via flawed parsing (15:16)
Lab #6 Host validation bypass via connection state attack (8:48)
Lab #7 Password reset poisoning via dangling markup (17:23)
Thank You!
Thank You!
Lab #6 Host validation bypass via connection state attack
Lesson content locked
If you're already enrolled,
you'll need to login
.
Enroll in Course to Unlock