crlf-payloads icon indicating copy to clipboard operation
crlf-payloads copied to clipboard

crlf-payloads

License contributions welcome

Proviesec logo Buy Me A Coffee

:star: Star us on GitHub — it motivates a lot! :star:

If you have some good CRLF payloads, just create a PullRequest.

Example

crlf%0D%20Header-Test:PROVIESEC

Todo

  • [ ] best crlf payloads
  • [ ] crlf reports
  • [ ] crlf attacks

Reports

https://hackerone.com/reports/590020 https://hackerone.com/reports/446271

writeup

https://infosecwriteups.com/6000-with-microsoft-hall-of-fame-microsoft-firewall-bypass-crlf-to-xss-microsoft-bug-bounty-8f6615c47922

Tutorial

  • Use burpsuite (Repeater)
  • Ffuf Master