S4E just found a medium-severity finding from host header injection vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Web Vulnerabilities·Updated Dec 16, 2023

X-Forwarded-For 403-forbidden Bypass Fuzz & Scanner

Detect 403 forbidden endpoint bypass behind Nginx/Apache proxy & load balancers, based on X-Forwarded-For header.

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
6.2k
Continuously Checked
assets under CS
479
Vulnerabilities Found
confirmed findings
References
Detail

The X-Forwarded-For (XFF) HTTP header field is a common method for identifying the originating IP address of a client connecting to a web server through an HTTP proxy or load balancer.


In cases where the recording mechanisms of web servers that can log HTTP headers fail to process the X-Forwarded-For header sent by the user, buffer overflow, command execution with web server rights, corruption of the file or format by entering corrupted data into the log files, etc. may be affected by security problems.

Solution Advice

Sanitize all parameters received as input from the user.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.