Web Hack List

Collected research

Scratching the surface of host headers in Safari

Safari accepts characters in a hostname that other browsers reject, so on sites with wildcard DNS the subdomain itself becomes the injection, reflected into HTML or passed to jQuery html(). Form-attribute payloads with a %0c inside the handler name evade the XSS auditor, and the same flaw in Safari's certificate error page made password manager extensions autofill credentials for the wrong site.

Record

Researcher
Linus Särud
Published by
Labs Detectify
Date
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Linus Särud, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .