↩️CRLF
Contexte
Connection: keep-alive
Content-Length: 178
Content-Type: text/html
Date: Mon, 09 May 2016 14:47:29 GMT
Location: https://www.example.com/location/path/here
X-Frame-Options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
<content>Vérification de la vulnérabilité
https://exemple.com/%0D%0ASet-Cookie:mycookie=S1rN3tZ Injections Avancées
CRLF to XSS
CRLF injection + HTML injection
Payloads
☠️Charges utilesBypass
GBK encoding
Outils
crlfuzz
Ressource
Mis à jour