CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Http Host Header Attacks

Http Host Header Attacks

Editor's Note

Covers the full playbook for exploiting applications that trust the Host header for URL generation, routing, or access control. The classic attack is password reset poisoning where you inject your domain in the Host header and the victim's reset token gets sent to you, but this also walks through cache poisoning, SSRF via routing, and virtual host discovery. What's useful here is the bypass catalog when Host validation exists: double Host headers, X-Forwarded-Host overrides, absolute URIs in the request line, and parser differentials with trailing dots or @ symbols. Includes framework-specific behaviors for PHP, Django, Rails, and Node that base models typically miss. If you're testing anything that generates links in emails or uses Host for backend routing, this gives you the complete enumeration checklist.

Install

npx skills add https://github.com/yaklang/hack-skills --skill http-host-header-attacks
Votes
0
Installs890
GitHub Stars862
Categories
Testing & QA
First SeenJun 3, 2026
View on GitHub

Comments

Login to comment

Related Testing & QA Skills

View all →
playwright-e2e-testing

bobmatnyc/claude-mpm-skills

0
2.7k
49
playwright e2e testing
qa-testing-playwright

vasilyu1983/ai-agents-public

0
423
60
qa testing playwright
playwright-e2e-testing

fugazi/test-automation-skills-agents

0
306
156
playwright e2e testing
e2e-testing-patterns

wshobson/agents

0
17.1k
36.2k
Comprehensive guide to building reliable, maintainable end-to-end test suites with Playwright and Cypress.
e2e-testing

affaan-m/everything-claude-code

0
5.1k
202.7k
e2e testing
typescript-e2e-testing

bmad-labs/skills

0
1.9k
9
typescript e2e testing