> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# HTTP Host Header Attacks

> Recursos cross-platform para HTTP Host Header Attacks: máquinas HTB, labs PortSwigger y rooms TryHackMe curados, con writeups validados y skills relacionadas.

# HTTP Host Header Attacks

Esta página agrega los **recursos para practicar HTTP Host Header Attacks** de forma cross-platform: máquinas retiradas de Hack The Box, labs de PortSwigger Web Security Academy y rooms de TryHackMe, más recursos curados (HackTricks, PortSwigger, etc.) y skills relacionadas.

## Recursos curados

| Fuente      | Enlace                                                                                               |
| ----------- | ---------------------------------------------------------------------------------------------------- |
| PortSwigger | [https://portswigger.net/web-security/host-header](https://portswigger.net/web-security/host-header) |

## Labs PortSwigger que practican HTTP Host Header Attacks (5)

| Lab                                                                                                                                                           | Dificultad                                                 | Topic                    | Oficial                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- | ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------- |
| [Host header authentication bypass](/portswigger/labs/host-header/exploiting-host-header-authentication-bypass)                                               | <span className="dbadge dbadge-easy">APPRENTICE</span>     | HTTP Host Header Attacks | [Abrir](https://portswigger.net/web-security/host-header/exploiting/lab-host-header-authentication-bypass)                              |
| [Host validation bypass via connection state attack](/portswigger/labs/host-header/exploiting-host-header-host-validation-bypass-via-connection-state-attack) | <span className="dbadge dbadge-medium">PRACTITIONER</span> | HTTP Host Header Attacks | [Abrir](https://portswigger.net/web-security/host-header/exploiting/lab-host-header-host-validation-bypass-via-connection-state-attack) |
| [Routing-based SSRF](/portswigger/labs/host-header/exploiting-host-header-routing-based-ssrf)                                                                 | <span className="dbadge dbadge-medium">PRACTITIONER</span> | HTTP Host Header Attacks | [Abrir](https://portswigger.net/web-security/host-header/exploiting/lab-host-header-routing-based-ssrf)                                 |
| [SSRF via flawed request parsing](/portswigger/labs/host-header/exploiting-host-header-ssrf-via-flawed-request-parsing)                                       | <span className="dbadge dbadge-medium">PRACTITIONER</span> | HTTP Host Header Attacks | [Abrir](https://portswigger.net/web-security/host-header/exploiting/lab-host-header-ssrf-via-flawed-request-parsing)                    |
| [Web cache poisoning via ambiguous requests](/portswigger/labs/host-header/exploiting-host-header-web-cache-poisoning-via-ambiguous-requests)                 | <span className="dbadge dbadge-medium">PRACTITIONER</span> | HTTP Host Header Attacks | [Abrir](https://portswigger.net/web-security/host-header/exploiting/lab-host-header-web-cache-poisoning-via-ambiguous-requests)         |

***

← [Volver al glosario completo](/glosario)

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"DefinedTerm","name":"HTTP Host Header Attacks","termCode":"host-header-attacks","inLanguage":"es","url":"https://rootea.es/skills/host-header-attacks","inDefinedTermSet":{"@type":"DefinedTermSet","name":"Glosario táctico de pentesting","url":"https://rootea.es/glosario"}}`}
</script>

*Última actualización: 2026-05-08*
