id: openvpn-hhi info: name: OpenVPN Host Header Injection author: twitter.com/Dheerajmadhukar severity: info description: A vulnerability in OpenVPN Access Server allows remote attackers to inject arbitrary redirection URLs by using the 'Host' HTTP header field. metadata: max-request: 1 tags: openvpn,hostheader-injection http: - raw: - | GET / HTTP/1.1 Host: {{randstr}}.tld matchers-condition: and matchers: - type: word words: - "https://{{randstr}}.tld/__session_start__/" - "openvpn_sess" part: header condition: and - type: status status: - 302 # digest: 4b0a00483046022100f76b69e227958efb15a05cbf8c374bc71d7ebae0043b64e3b3b5f5edd1f0a2b8022100f45b19f31f955e4b92c297240c02aae6380c24585ab704edd092391657de9184:922c64590222798bb761d5b6d8e72950