A security analyst is performing a penetration test against a web application. During the reconnaissance phase, the analyst uses a tool to send a specially crafted HTTP request to the target server: ``` GET / HTTP/1.1 Host: example.com User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Accept-Language: en-US,en;q=0.9 Accept-Encoding: gzip, deflate Connection: keep-alive X-Forwarded-For: 127.0.0.1 ``` The analyst observes that the server's response includes the `X-Forwarded-For` header with the value `127.0.0.1` in the response, while other requests without this header do not. This indicates the presence of a proxy or load balancer that is reflecting the header. Which vulnerability or misconfiguration is the analyst attempting to identify?
- AHTTP Host Header Injection
- BImproper Input Validation for `X-Forwarded-For`
- CCross-Site Request Forgery (CSRF)
- DServer-Side Request Forgery (SSRF)
Show answer & explanationAnswer & explanation
Correct answer: B. Improper Input Validation for `X-Forwarded-For`
The analyst is testing how the server handles the `X-Forwarded-For` header. When the server reflects `127.0.0.1` back, it indicates that a proxy or load balancer is in front of the application server. The vulnerability isn't necessarily the reflection itself, but the potential for improper input validation of this header. Attackers can manipulate `X-Forwarded-For` to bypass IP-based access controls, poison caches, or even inject other headers if not properly sanitized by the application or proxy. The act of the server reflecting it back means it's being processed, and thus, potentially vulnerable to misinterpretation or injection if validation is lacking.
Why the other options are wrong
- A. HTTP Host Header Injection involves manipulating the `Host` header, not `X-Forwarded-For`, to redirect users or poison caches.
- C. CSRF is an attack where an attacker tricks a web browser into executing an unwanted action on a trusted site where the user is authenticated. This test is not related to CSRF.
- D. SSRF involves tricking a server into making requests to an arbitrary domain of the attacker's choosing. While `X-Forwarded-For` can sometimes be part of SSRF exploits, the primary observation here is the server's handling and reflection of the header, pointing to its specific validation.
X-Forwarded-For Header Abuse
The `X-Forwarded-For` (XFF) HTTP header identifies the originating IP address of a client connecting to a web server through an HTTP proxy or load balancer. If not properly validated, attackers can manipulate this header to bypass IP-based access controls, poison web caches, or impersonate other users.
- Indicates client's original IP when behind a proxy.
- Manipulating it can bypass IP-based security controls.
- Requires proper validation by the application or proxy.
Memory trick: Headers are like the envelope information for web requests.