What's new

Closed How to bypass 302 with crlf injection method?

Status
Not open for further replies.

belege

Addict
Guys, anyone that knows, I need help.
I need to bypass my isp firewall that redirects even the free sites with a 302 found. The only exeption is the 0.fb site.
I know that this is possible with a crlf/header/split injection in the payload. That means that the request has to be interupted with a move or head request(i think) in order to inject the custom headers. Can you give me a payload example and maybe any tip that I have to care about? Thanks.
 
I dont know if its the hosts problem. I think that the way the payload is written does all tbe job. I found this payload from another group in telegram
OPTIONS You do not have permission to view the full content of this post. Log in or register now. HTTP/1.1[lf][lf][method] [host_port] HTTP/1.1[delay_split]MOVE :[delay_split][lf]Host: bug/[ssh][crlf]

Whateve site i use in bug it connects...For example I can use You do not have permission to view the full content of this post. Log in or register now. or whatever else, and still connects..So its about the way the payload is written. But the problem is that this payload disconnects me after some seconds because of ilegal packet size error..I am kinda in a dead end here..
 
Status
Not open for further replies.

Similar threads

Back
Top