EvilZone

Hacking and Security => Hacking and Security => : M1lak0 March 07, 2014, 08:27:33 PM

: HTTP/HTTPS Header Manipulation
: M1lak0 March 07, 2014, 08:27:33 PM
Please help me with basic starting of this attack and some useful link...
I tried finding such tutorials on attack based on this but couldn't found much!
Thank u in advance! :)
: Re: HTTP/HTTPS Header Manipulation
: lucid March 07, 2014, 08:46:24 PM
1 - How long did you actually search for?

2 - This is not the place to request help, this is the place to post tutorials. So, moved.
: Re: HTTP/HTTPS Header Manipulation
: M1lak0 March 08, 2014, 01:28:12 PM
I tried a youtube search but no attack was mentioned there or gave any kind of tutorial.
httpfox and temperdata. but i want to know how can an attack carried out with this any useful link would also do. :)
: Re: HTTP/HTTPS Header Manipulation
: ThePH30N1X March 08, 2014, 04:25:39 PM
You should take a look at programs like Burp Suite and WebScarab. I wrote a program that could do this, but it's not public yet (And very minimalistic).
: Re: HTTP/HTTPS Header Manipulation
: M1lak0 March 08, 2014, 05:34:12 PM
Thank you ThePH30N1X (https://evilzone.org/profile/?u=17848) for your guidance.. :)
You should take a look at programs like Burp Suite and WebScarab. I wrote a program that could do this, but it's not public yet (And very minimalistic).
: Re: HTTP/HTTPS Header Manipulation
: Teapot March 08, 2014, 08:36:32 PM
You should take a look at programs like Burp Suite and WebScarab. I wrote a program that could do this, but it's not public yet (And very minimalistic).

Thank you ThePH30N1X (https://evilzone.org/profile/?u=17848) for your guidance.. :)

REALLY???
EZ is not a skid factory. If all you want is too brag to your friends or all you care about is the destination then go to fucking HF and download Cain&Abel infected by some other skid.
: Re: HTTP/HTTPS Header Manipulation
: lucid March 08, 2014, 10:36:15 PM
I tried a youtube search but no attack was mentioned there or gave any kind of tutorial.
Yeah you're right there must not be any resources out there then...
: Re: HTTP/HTTPS Header Manipulation
: Axon March 08, 2014, 11:00:02 PM
Here's some detailed examples.I hope this helps?

http://xss.cx/examples/dork/http-injection/http-header-injection-0x20-crlf-splitting.travel.travelocity.com.html (http://xss.cx/examples/dork/http-injection/http-header-injection-0x20-crlf-splitting.travel.travelocity.com.html)
: Re: HTTP/HTTPS Header Manipulation
: M1lak0 March 10, 2014, 12:39:55 PM
You'll have to be more specific about your question here. Do you want to know about attacks like HTTP Response Splitting? If so check out https://www.owasp.org/index.php/HTTP_Response_Splitting (https://www.owasp.org/index.php/HTTP_Response_Splitting) . In fact, check out OWASP for anything web app hacking related and you'll often get a plethora of info
Here's some detailed examples.I hope this helps?

http://xss.cx/examples/dork/http-injection/http-header-injection-0x20-crlf-splitting.travel.travelocity.com.html (http://xss.cx/examples/dork/http-injection/http-header-injection-0x20-crlf-splitting.travel.travelocity.com.html)

WOW Thank you guys to share me few link and help.
I have actually tried xss and sqli via header manipulation but I want to play and explore more about this and few ways. Well I'll Surely check these links and let you know about it! :D
Is there any other types of attack based on Header manipulation? Please let me know!
Thank you all for your reply. . .
: Re: HTTP/HTTPS Header Manipulation
: proxx March 11, 2014, 11:48:56 AM
WOW Thank you guys to share me few link and help.
I have actually tried xss and sqli via header manipulation but I want to play and explore more about this and few ways. Well I'll Surely check these links and let you know about it! :D
Is there any other types of attack based on Header manipulation? Please let me know!
Thank you all for your reply. . .
https://evilzone.org/hacking-and-security/session-hijacking-evilzone/msg72536/#msg72536
No longer works coz they finally fixed it :)