TGViewer
Casual Blog Casual Blog @casualblog · 436 subscribers
Post #86 832
HowWorks CRLF

‘HowWorks’ - new post type, explains how something works, in that case CRLF vulnerability
If we can inject some data in web app that doesn’t get proper validation/filtering and used in HTTP response Headers, then we can inject \r\n (HTTP line break, CRLF).

You can think of it as stored XSS, but instead Javascript, we inject \r\n which will allow to effectivly modify entire HTTP response from server to specific endpoint.

Example - set name to username%0d%0aLocation:http://malicioussite.com/ to redirect anyone who access your username in url.

Impact:

● XSS
● Log Injection
● HTTP Header Injection
● HTTP Response Splitting
● Log Tampering
● Cookie Injection
● Phishing
● Web Cache Poisoning

It’s a rare bug nowadays.
Truth be told, I thought it’s more complex

----------------------
Sources
● https://owasp.org/www-community/vulnerabilities/CRLF_Injection
● https://www.imperva.com/learn/application-security/crlf-injection/

via Casual Blog
  • ❤ 1
More from @casualblog
  1. Feb 13, 2026Blog: Domain is Gone ## DNS Thanks to Namecheap I’m ultimately distrust centrilized DNS so…
  2. Dec 26, 2025Blog: Domain Issues via Casual Blog
  3. Dec 5, 2025CVE-2025-55182 WILD! Jokes on me, CVE-2025-55182 is cool! Literally POST / = RCE. Status p…
  4. Dec 3, 2025CVE-2025-55182 is overhyped CVE-2025-55182 is a 10.0 CRITICAL vulnerability. Thou it’s not…
  5. Dec 2, 2025HowTo Bruteforce Owncloud By default Owncloud doesn’t have any account locking or login ra…
  6. Oct 1, 2025HowIs Standoff Hacks Ahmedabad Hi! I was at Standoff Hacks Ahmedabad. It’s a priv8 bugboun…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →