Re: Hostheader attack vulnerability

2022-12-15 Thread Mark Thomas
There isn't anything here that indicates there there is a problem for Tomcat to solve. You appear to be using a tool provided by Cisco. I suggest you contact Cisco for support. If you still believe that there is a Tomcat issue here please provide: - Full details (including HTTP headers) of

Hostheader attack vulnerability

2022-12-14 Thread Ragavendhiran Bhiman (rabhiman)
Hi All, I am facing one issue related to host header manipulation changing the host header is chaning the url itself. This attack is done via the burp suite tool. I have copied the current configuration here as you could see the default hostname is defined and apBase is provided. The attack