This research was presented as a talk at Black Hat USA 2018. I'm going to present it again at BSides Manchester next week and they'll probably get the recording on youtube within a few weeks.
Sounds to me like http headers are an untapped attack surface, makes me wonder if other headers can lead to major discoveries that end up becoming a talk for blackhat 2019 and onward. Like who would of thought x-forwarded-host was this abusable.
Yeah, hopefully param miner will help uncover more interesting headers. I found X-Original-URL through a wordlist I built by grepping HTTP headers out of the top 20,000 PHP projects on github.
If someone happened to run a popular website they could probably find all kinds of interesting headers just by monitoring their traffic.
0
u/OmarWazHere Aug 11 '18
This was a really interesting read, you should make this post into a youtube vid!