duck.http.middlewares.security.modules.header_injection

Module Contents

Functions

check_header_injection

Ultra-fast detection of header injection, session fixation, XSS, open redirect, and cache poisoning attacks.

Data

CACHE_POISON_RE

COOKIE_FORMAT_RE

CRLF_RE

SCRIPT_TAG_RE

API

duck.http.middlewares.security.modules.header_injection.CACHE_POISON_RE

‘compile(…)’

duck.http.middlewares.security.modules.header_injection.COOKIE_FORMAT_RE

‘compile(…)’

duck.http.middlewares.security.modules.header_injection.CRLF_RE

‘compile(…)’

duck.http.middlewares.security.modules.header_injection.SCRIPT_TAG_RE

‘compile(…)’

duck.http.middlewares.security.modules.header_injection.check_header_injection(headers: dict)

Ultra-fast detection of header injection, session fixation, XSS, open redirect, and cache poisoning attacks.

Returns:

Tuple (bool, str) indicating if an attack is found and its type.

Return type:

(result, attack_type)