Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

3
  • thanks for your insight. I am thinking that one scenario could be to trick user into somehow installing some browser plugin which might change Host header, but likelihood seems extremely low. Commented Jun 29, 2017 at 11:28
  • 4
    Then you can also trick the user into installing a browser plugin that does far more evil stuff. Commented Jun 29, 2017 at 12:06
  • @iain: to cite myself: you gain not really anything new by modifying the Host header in the request since as a man in the middle you could already modify the Location header in the response anyway Commented Jun 29, 2017 at 13:38