3

What are good tools for finding CRLF injection vulnerabilities?

Gilles 'SO- stop being evil'
  • 50,912
  • 13
  • 120
  • 179
Daniel
  • 1,422
  • 3
  • 21
  • 32

1 Answers1

1

CRLF injection can be used in IMAP/SMTP command injection and in HTTP Response Splitting. In both cases BURP is the tool of choice.

Wapiti is a FOSS vulnerability scanner that can detect http response splitting. The vast majority vulnerability scanners should be able to detect this attack.

rook
  • 46,916
  • 10
  • 92
  • 181