werdlists

:keyboard: Wordlists, Dictionaries and Other Data Sets for Writing Software Security Test Cases

View on GitHub

werdlists/http-headers

        Folder  Name         Description of Contents
about-http-headers Descriptions for the most common HTTP header fields
access-control-headers Cross Origin Resource Sharing (CORS) header name list
amazon-http-headers HTTP headers specific to Amazon
cloudfront-request-headers Headers used by Amazon AWS CloudFront HTTP request
cors-request-headers CORS header names used only in HTTP requests
cors-response-headers CORS header names used only in HTTP responses
custom-header-names HTTP request and response header names unspecified in RFC’s
custom-request-headers non-standard HTTP request headers, i.e. lack RFC specs
custom-response-headers non-standard HTTP response headers, i.e. lack RFC specs
envoy-httpconnman-headers headers used by the Envoy HTTP connection manager
http-request-headers names of all standard HTTP request header fields
http-response-headers names of all standard HTTP response header fields
iana-headers-list A detailed list of message headers specified by IANA
iana-http-headers Uniquely Sorted List of IANA Message Headers Assignments
meetup-request-headers HTTP request headers used by the MeetUp.com API
meetup-response-headers HTTP response headers used by the MeetUp.com API
mozdev-docs-headers list from left sidebar of Mozilla Developer Docs HTTP Headers pages
permanent-message-headers Permanent Message Header Field Names
provisional-message-headers Provisional Message Header Field Names
platform-request-headers request headers that are specific to certain platforms
platform-response-headers response headers particular to certain platforms
rfc-request-headers request header names that appear in an IETF RFC document
rfc-response-headers response header names that appear in an IETF RFC document
security-policy-headers Content Security Policy (CSP) header name list
ssrf-headers-addr Server-Side Request Forgery (SSRF) request header names ending with the substring -Addr
ssrf-headers-address SSRF request header names ending with the substring -Address
ssrf-headers-all All of the SSRF request header names files’ contents combined subsequent to unique sorting along with those that have been manually added
ssrf-headers-auto SSRF request headers automatically generated from ssrf-headers-all by scripts/ssrf-headers-auto
ssrf-headers-dns SSRF request header names ending with the substring -DNS
ssrf-headers-host SSRF request header names ending with the substring -Host
ssrf-headers-ip SSRF request header names ending with the substring -IP
ssrf-headers-server SSRF request header names ending with the substring -Server
ssrf-headers-vanilla SSRF request header names without any specific appendage
ssrf-request-headers request headers that can be used in SSRF attacks
ssrf-response-headers response headers host names for SSRF can be parsed from
tusio-http-headers headers used by resumable file transfer protocol, see tus.io