Collected research
Scratching the surface of host headers in Safari
Safari accepts characters in a hostname that other browsers reject, so on sites with wildcard DNS the subdomain itself becomes the injection, reflected into HTML or passed to jQuery html(). Form-attribute payloads with a %0c inside the handler name evade the XSS auditor, and the same flaw in Safari's certificate error page made password manager extensions autofill credentials for the wrong site.
Record
- Researcher
- Linus Särud
- Published by
- Labs Detectify
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Linus Särud, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .