daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (3894B)


      1 ---
      2 title: "Virtual Host"
      3 topic: "Virtual Hosts"
      4 topicSlug: "virtual-hosts"
      5 sourcePath: "Virtual Hosts/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Virtual%20Hosts/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Virtual Host
     12 
     13 > A **Virtual Host** (VHOST) is a mechanism used by web servers (e.g., Apache, Nginx, IIS) to host multiple domains or subdomains on a single IP address. When enumerating a webserver, default requests often target the primary or default VHOST only. **Hidden hosts** may expose extra functionality or vulnerabilities.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19 * [References](#references)
     20 
     21 ## Tools
     22 
     23 * [wdahlenburg/VhostFinder](https://github.com/wdahlenburg/VhostFinder) - Identify virtual hosts by similarity comparison.
     24 * [codingo/VHostScan](https://github.com/codingo/VHostScan) - A virtual host scanner that can be used with pivot tools, detect catch-all scenarios, aliases and dynamic default pages.
     25 * [hakluke/hakoriginfinder](https://github.com/hakluke/hakoriginfinder) - Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs.
     26 
     27     ```ps1
     28     prips 93.184.216.0/24 | hakoriginfinder -h https://example.com:443/foo
     29     ```
     30 
     31 * [OJ/gobuster](https://github.com/OJ/gobuster) - Directory/File, DNS and VHost busting tool written in Go.
     32 
     33     ```ps1
     34     gobuster vhost -u https://example.com -w /path/to/wordlist.txt
     35     ```
     36 
     37 ## Methodology
     38 
     39 When a web server hosts multiple websites on the same IP address, it uses **Virtual Hosting** to decide which site to serve when a request comes in.
     40 
     41 In HTTP/1.1 and above, every request must contain a `Host` header:
     42 
     43 ```http
     44 GET / HTTP/1.1
     45 Host: example.com
     46 ```
     47 
     48 This header tells the server which domain the client is trying to reach.
     49 
     50 * If the server only has one site: The `Host` header is often ignored or set to a default.
     51 * If the server has multiple virtual hosts: The web server uses the `Host` header to route the request internally to the right content.
     52 
     53 Suppose the server is configured like:
     54 
     55 ```ps1
     56 <VirtualHost *:80>
     57     ServerName site-a.com
     58     DocumentRoot /var/www/a
     59 </VirtualHost>
     60 
     61 <VirtualHost *:80>
     62     ServerName site-b.com
     63     DocumentRoot /var/www/b
     64 </VirtualHost>
     65 ```
     66 
     67 A request with the default host ("site-a.com") returns the content for Site A.
     68 
     69 ```http
     70 GET / HTTP/1.1
     71 Host: site-a.com
     72 ```
     73 
     74 A request with an altered host ("site-b.com") returns content for Site B (possibly revealing something new).
     75 
     76 ```http
     77 GET / HTTP/1.1
     78 Host: site-b.com
     79 ```
     80 
     81 ### Fingerprinting VHOSTs
     82 
     83 Setting `Host` to other known or guessed domains may give **different responses**.
     84 
     85 ```ps1
     86 curl -H "Host: admin.example.com" http://10.10.10.10/
     87 ```
     88 
     89 Common indicators that you're hitting a different VHOST:
     90 
     91 * Different HTML titles, meta descriptions, or brand names
     92 * Different HTTP Content-Length / body size
     93 * Different status codes (200 vs. 403 or redirect)
     94 * Custom error pages
     95 * Redirect chains to completely different domains
     96 * Certificates with Subject Alternative Names listing other domains
     97 
     98 **NOTE**: Leverage DNS history records to identify old IP addresses previously associated with your target’s domains. Then test (or "spray") the current domain names against those IPs. If successful, this can reveal the server’s real address, allowing you to bypass protections like Cloudflare or other WAFs by interacting directly with the origin server.
     99 
    100 ## References
    101 
    102 * [Gobuster for directory, DNS and virtual hosts bruteforcing - erev0s - March 17, 2020](https://web.archive.org/web/20200925023215/https://erev0s.com/blog/gobuster-directory-dns-and-virtual-hosts-bruteforcing/)
    103 * [Virtual Hosting – A Well Forgotten Enumeration Technique - Wyatt Dahlenburg - June 16, 2022](https://web.archive.org/web/20220616183823/https://wya.pl/2022/06/16/virtual-hosting-a-well-forgotten-enumeration-technique/)