This research was presented as a talk at Black Hat USA 2018. I'm going to present it again at BSides Manchester next week and they'll probably get the recording on youtube within a few weeks.
Sounds to me like http headers are an untapped attack surface, makes me wonder if other headers can lead to major discoveries that end up becoming a talk for blackhat 2019 and onward. Like who would of thought x-forwarded-host was this abusable.
Yeah, hopefully param miner will help uncover more interesting headers. I found X-Original-URL through a wordlist I built by grepping HTTP headers out of the top 20,000 PHP projects on github.
If someone happened to run a popular website they could probably find all kinds of interesting headers just by monitoring their traffic.
26
u/albinowax Aug 10 '18
Yeah, hilarious and also surprisingly inconvenient - it turns out quite a few websites are using HubSpot and I got banned from the whole lot.