HTTP Response Splitting

HTTP Response Splitting is an attack type that allows attacker to embed arbitrary data via HTTP response headers.

Attack is aimed at the inserting linefeed symbols into HTTP headers given by web server, so that an attacker can completely change the content of the server response and displayed page.

  • Carriage Return = %0d = \r
  • Line Feed = %0a = \n

