HTTP Response Splitting

70 Points  0x0

Old vulnerability... but powerful !

Author

Arod,  

Level  Difficulty

Validations

2500 Challengers 1%

Note  Notation

228 Votes

To reach this part of the site please login
You should validate this challenge first

Challenge Results Challenge Results

Pseudo Challenge Lang Date
louis.la3 Web - Client  HTTP Response Splitting fr 23 April 2023 at 21:19
Asta ♧ Web - Client  HTTP Response Splitting fr 22 April 2023 at 17:39
0x0d1n Web - Client  HTTP Response Splitting fr 19 April 2023 at 18:56
kibatche Web - Client  HTTP Response Splitting fr 19 April 2023 at 18:16
StorrmHell Web - Client  HTTP Response Splitting fr 18 April 2023 at 13:55
tagg Web - Client  HTTP Response Splitting fr 17 April 2023 at 11:17
Céline Pieczuk Web - Client  HTTP Response Splitting fr 16 April 2023 at 15:06
HitCat Web - Client  HTTP Response Splitting fr 14 April 2023 at 22:47
mathippo18 Web - Client  HTTP Response Splitting fr 14 April 2023 at 14:58
Anonymous Web - Client  HTTP Response Splitting fr 12 April 2023 at 21:49

challenges 42 Challenges

Results Name Validations Number of points  Explanation for the scores Difficulty  Difficulty Author Note  Notation Solution Date
pas_valide Same Origin Method Execution 1% 53 90 Mizu 0 28 July 2023
pas_valide Browser - bfcache / disk cache 1% 77 65 Mizu 0 28 July 2023
pas_valide CSPT - The Ruler 1% 80 60 Rolix , Mizu 0 27 September 2024
pas_valide Self XSS - Race Condition 1% 112 60 Mizu 1 28 July 2023
pas_valide Javascript - Obfuscation 6 1% 130 60 n3rada 0 27 April 2023
pas_valide XS Leaks 1% 213 75 Mizu 1 8 April 2022
pas_valide Relative Path Overwrite 1% 216 50 Mizu 2 28 July 2023
pas_valide Self XSS - DOM Secrets 1% 278 55 Mizu 3 28 July 2023
pas_valide DOM Clobbering 1% 446 60 Mizu 1 8 April 2022
pas_valide CSP Bypass - Nonce 2 1% 680 35 Ruulian 1 27 June 2023
pas_valide CSS - Exfiltration 1% 707 50 Forgi , gwel 1 8 April 2022
pas_valide Javascript - Obfuscation 5 1% 823 70 Hel0ck 3 4 February 2011
pas_valide XSS - DOM Based 1% 885 85 vic 6 24 December 2016
pas_valide Web Socket - 0 protection 1% 973 35 Worty 1 22 October 2021
pas_valide CSP Bypass - Nonce 1% 1158 50 Ruulian 4 8 April 2022
pas_valide CSP Bypass - JSONP