{"id":9712,"date":"2021-03-11T12:55:17","date_gmt":"2021-03-11T07:25:17","guid":{"rendered":"https:\/\/www.varutra.com\/?p=9712"},"modified":"2022-12-02T13:09:47","modified_gmt":"2022-12-02T07:39:47","slug":"crlf-carriage-return-line-feed-injection","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/","title":{"rendered":"CRLF Injection"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2021\/03\/CRLF-1024x573.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"CRLF Injection - Varutra Consulting\"><br \/>\nBefore going into details on what and how to find and perform CRLF injection and what are the measure one should take from this to happen, we will first get to know a little bit about what exactly is CRLF (Carriage Return Line Feed) and why it is used.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>So, what exactly is CRLF (Carriage Return Line Feed)?<\/strong><\/h3>\n<p>In CRLF, CR stands for Carriage Return and LR stands for Line Feed. Carriage Return is represented by \u201c\\r\u201d (ASCII value 13) and Line Feed is represented by \u201c\\n\u201d (ASCII value 10).Carriage Return refers to end of a line, and Line Feed refers to a new line. Thus, CR and LF both combined are used to denote ending of a line.<\/p>\n<p>When a request is sent to a web server, it sends back a response containing HTTP headers and the content. These HTTP headers and the HTML response i.e. the web content in the response from the server are separated by a combination of some special characters; these characters are CR and LF.So basically, CRLF is used to separate HTTP headers and HTML content in a response from the server.So, in short CRLF is used to denote a new line.<\/p>\n<p>CRLF characters are used by most of the servers like Microsoft IIS, Apache, and all others. Mostly in Windows both CR and LF are used to terminate a line, whereas in LINUX\/UNIX only LF is used. Many protocols like MIME, NNTP and most widely HTTP use CR-LF sequence.\u00a0 The HTTP protocol always uses CR-LF sequence to terminate a line.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What is CRLF injection?<\/strong><\/h3>\n<p>CRLF injection vulnerability attack is where an attacker will try to inject a CRLF sequence into an unexpected input field of an application. This input of an unexpected CRLF sequence will trick the application to perform in such a way where potential security flaws may arise. Using CRLF injection the attackers can further exploit various vulnerabilities like XSS (Cross-Site Scripting), <a href=\"https:\/\/www.varutra.com\/2020\/11\/27\/web-cache-poisoning-through-host-header-injection\/\">Web cache poisoning<\/a>, Script injection, Phishing attacks, client session hijacking, etc. The vulnerabilities can range from medium to high severity.<\/p>\n<p>There are 2 most important use cases for CRLF injection. First one being Log poisoning and the second one is HTTP response splitting.<\/p>\n<ol>\n<li>Log poisoning: In this case the attacker will try to falsify the log entries by adding an end of line and an extra line. This will confuse the system administrators or hide other attacks.<\/li>\n<li>HTTP response splitting: In this case the attacker will use CRLF injection to add HTTP headers to the response. This will help in performing other attacks, like XSS which can further lead to information disclosure.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h3><strong>Cause of CRLF injection<\/strong>:<\/h3>\n<p>CRLF injection is mostly found in <a href=\"https:\/\/www.varutra.com\/2021\/01\/28\/http-request-smuggling\/\">HTTP request<\/a>. This may arise when a web application accepts a user input without properly validating it from an untrusted source.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>How to check if the website or web app is vulnerable to CRLF injection or not?<\/strong><\/h3>\n<p>For checking if a particular website is vulnerable to this type of injection, first we have to check whether there is any user input field in that page, that is later being used to set the response cookie. This is the key indicator that something is there in the application when we can manipulate in setting a cookie. If there is any input of this kind, then we can check for any \u201cGET\u201d method and then try to insert %0d%0a into that GET response and check whether the website is vulnerable to CRLF injection.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Examples of CRLF<\/strong>:<\/h3>\n<ol>\n<li>Request: GET \/%0d%0aSet-Cookie:CRLFInjection=P HTTP\/1.1<\/li>\n<\/ol>\n<p>Look at the above GET request, if the attacker is able to successfully inject CRLF sequence into this website then the attacker will be able to set the cookie for the website as shown above.<\/p>\n<p>&nbsp;<\/p>\n<ol start=\"2\">\n<li>Let\u2019s look at another example where the attacker will successfully be able to add logs in a system to trick the system administrator.<\/li>\n<\/ol>\n<p>Log: 123.123.123.123 &#8211; 08:15 &#8211; \/index.php?page=home<\/p>\n<p>Suppose there is a log file in an admin panel. The pattern of the output stream is \u201cIP-Time-Visited path\u201d as shown above.<\/p>\n<p>If the attacker can successfully perform CRLF injection into this file, then he will be able to add fake log entries. To do so he will try something like what is shown below to change the request.<\/p>\n<p>Request: <u>\/index.php?page=home&amp;%0d%0a127.0.0.1 &#8211; 08:15 &#8211;\u00a0\u00a0\u00a0\u00a0\u00a0 <\/u><\/p>\n<p><u>\/index.php?page=home&amp;restrictedaction=edit<\/u><\/p>\n<p>After successfully executing this request the log entries in the admin panel will look like:<\/p>\n<p>Logs: 123.123.123.123 &#8211; 08:15 &#8211; \/index.php?page=home&amp;<br \/>\n127.0.0.1 &#8211; 08:15 &#8211; \/index.php?page=home&amp;restrictedaction=edit<\/p>\n<p>Thus, by exploiting CRLF injection the attacker was able to successfully add fake log entries into the admin panel log file.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Impacts of CRLF injection<\/strong>:<\/h3>\n<p>There are lot of impacts and scenarios that can arise from exploiting CRLF injection. Like CRLF injection can be used to inject malicious scripts and perform XSS, it can also be used to set client-side cookies, etc. We will not discuss all the impacts; here we will just try some of them.<\/p>\n<ol>\n<li>Client-Side Cookie injection: Here in this scenario we are trying to set a fake cookie in the application by exploiting CRLF injection vulnerability.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-9713 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/Client-Side-Cookie-injection.png\" alt=\"Exploiting CRLF injection vulnerability\" width=\"586\" height=\"154\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Client-Side-Cookie-injection.png 586w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Client-Side-Cookie-injection-300x79.png 300w\" sizes=\"(max-width: 586px) 100vw, 586px\" \/><\/p>\n<ol start=\"2\">\n<li>Redirection and javascript execution: In this scenario we are injection a malicious script in a redirection request in combination with the CRLF characters and trying to bypass the filter.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-9714\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/Redirection-and-javascript-execution.png\" alt=\"Redirection and javascript execution for Carriage Return Line Feed\" width=\"584\" height=\"218\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Redirection-and-javascript-execution.png 584w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/Redirection-and-javascript-execution-300x112.png 300w\" sizes=\"(max-width: 584px) 100vw, 584px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Mitigations<\/strong>:<\/h3>\n<p>Mitigation recommended for prevention of CRLF injection are as follows \u2013<\/p>\n<ul>\n<li>Always sanitize and validate user supplied inputs.<\/li>\n<li>Always encode CR-LF and other special characters.<\/li>\n<li>Validate every input before they reach to response headers.<\/li>\n<li>Disable unnecessary headers.<\/li>\n<\/ul>\n<p>That was it about CRLF injection in this blog. Hope this was help in understanding about the vulnerability.<\/p>\n<p style=\"text-align: center\"><u>Thank You.<\/u><\/p>\n<p>&nbsp;<\/p>\n<p>Author,<\/p>\n<p><strong>Pralekya H.<\/strong><\/p>\n<p>Attack &amp; Pentest Team<\/p>\n<p>Varutra Consulting Pvt. Ltd.<\/p>","protected":false},"excerpt":{"rendered":"<p>Before going into details on what and how to find and perform CRLF injection and what are the measure one should take from this to&#8230;<\/p>\n","protected":false},"author":4,"featured_media":9716,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[57,272],"tags":[550,397,551,396],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.6.3 - aioseo.com -->\n\t\t<meta name=\"description\" content=\"Find and perform CRLF injection vulnerability, what exactly is CRLF (Carriage Return Line Feed), and what are the measure one should take from this to happen.\" \/>\n\t\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.6.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"CRLF Injection Vulnerability and Precaution Measures\" \/>\n\t\t<meta property=\"og:description\" content=\"Find and perform CRLF injection vulnerability, what exactly is CRLF (Carriage Return Line Feed), and what are the measure one should take from this to happen.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/CRLF.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/CRLF.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1060\" \/>\n\t\t<meta property=\"og:image:height\" content=\"593\" \/>\n\t\t<meta property=\"article:section\" content=\"Web Application Security\" \/>\n\t\t<meta property=\"article:tag\" content=\"carriage return line feed\" \/>\n\t\t<meta property=\"article:tag\" content=\"crlf\" \/>\n\t\t<meta property=\"article:tag\" content=\"crlf injection\" \/>\n\t\t<meta property=\"article:tag\" content=\"http request\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-03-11T07:25:17+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T07:39:47+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"CRLF Injection Vulnerability and Precaution Measures\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Find and perform CRLF injection vulnerability, what exactly is CRLF (Carriage Return Line Feed), and what are the measure one should take from this to happen.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/CRLF.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpblogger\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#article\",\"name\":\"CRLF Injection Vulnerability and Precaution Measures\",\"headline\":\"CRLF Injection\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/CRLF.png\",\"width\":1060,\"height\":593,\"caption\":\"CRLF Injection\"},\"datePublished\":\"2021-03-11T12:55:17+05:30\",\"dateModified\":\"2022-12-02T13:09:47+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#webpage\"},\"articleSection\":\"Vulnerability Disclosure, Web Application Security, Carriage Return Line Feed, CRLF, CRLF Injection, HTTP request\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"nextItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#listItem\"},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#listItem\",\"position\":2,\"name\":\"CRLF Injection\",\"previousItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\"}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/\",\"name\":\"kalpblogger\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"kalpblogger\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/\",\"name\":\"CRLF Injection Vulnerability and Precaution Measures\",\"description\":\"Find and perform CRLF injection vulnerability, what exactly is CRLF (Carriage Return Line Feed), and what are the measure one should take from this to happen.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/CRLF.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#mainImage\",\"width\":1060,\"height\":593,\"caption\":\"CRLF Injection\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/crlf-carriage-return-line-feed-injection\\\/#mainImage\"},\"datePublished\":\"2021-03-11T12:55:17+05:30\",\"dateModified\":\"2022-12-02T13:09:47+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>CRLF Injection Vulnerability and Precaution Measures<\/title>\n\n","aioseo_head_json":{"title":"CRLF Injection Vulnerability and Precaution Measures","description":"Find and perform CRLF injection vulnerability, what exactly is CRLF (Carriage Return Line Feed), and what are the measure one should take from this to happen.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"CRLF Injection Vulnerability and Precaution Measures","og:description":"Find and perform CRLF injection vulnerability, what exactly is CRLF (Carriage Return Line Feed), and what are the measure one should take from this to happen.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/CRLF.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/CRLF.png","og:image:width":"1060","og:image:height":"593","article:section":"Web Application Security","article:tag":["carriage return line feed","crlf","crlf injection","http request"],"article:published_time":"2021-03-11T07:25:17+00:00","article:modified_time":"2022-12-02T07:39:47+00:00","twitter:card":"summary_large_image","twitter:title":"CRLF Injection Vulnerability and Precaution Measures","twitter:description":"Find and perform CRLF injection vulnerability, what exactly is CRLF (Carriage Return Line Feed), and what are the measure one should take from this to happen.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/CRLF.png","twitter:label1":"Written by","twitter:data1":"kalpblogger","twitter:label2":"Est. reading time","twitter:data2":"5 minutes","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#article","name":"CRLF Injection Vulnerability and Precaution Measures","headline":"CRLF Injection","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/CRLF.png","width":1060,"height":593,"caption":"CRLF Injection"},"datePublished":"2021-03-11T12:55:17+05:30","dateModified":"2022-12-02T13:09:47+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#webpage"},"articleSection":"Vulnerability Disclosure, Web Application Security, Carriage Return Line Feed, CRLF, CRLF Injection, HTTP request"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3\/","nextItem":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#listItem"},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#listItem","position":2,"name":"CRLF Injection","previousItem":"https:\/\/www.varutra.com\/varutravrt3\/#listItem"}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/","name":"kalpblogger","image":{"@type":"ImageObject","@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g","width":96,"height":96,"caption":"kalpblogger"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/","name":"CRLF Injection Vulnerability and Precaution Measures","description":"Find and perform CRLF injection vulnerability, what exactly is CRLF (Carriage Return Line Feed), and what are the measure one should take from this to happen.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/03\/CRLF.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#mainImage","width":1060,"height":593,"caption":"CRLF Injection"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/#mainImage"},"datePublished":"2021-03-11T12:55:17+05:30","dateModified":"2022-12-02T13:09:47+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]}},"aioseo_meta_data":{"post_id":"9712","title":"CRLF Injection Vulnerability and Precaution Measures","description":"Find and perform CRLF injection vulnerability, what exactly is CRLF (Carriage Return Line Feed), and what are the measure one should take from this to happen.","keywords":[],"keyphrases":"{\"focus\":{\"keyphrase\":\"CRLF Injection\",\"analysis\":{\"keyphraseInTitle\":{\"title\":\"Focus keyphrase in SEO title\",\"description\":\"Focus keyphrase found in SEO title.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInDescription\":{\"title\":\"Focus keyphrase in meta description\",\"description\":\"Focus keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Focus keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":2},\"keyphraseInURL\":{\"title\":\"Focus keyphrase in URL\",\"description\":\"Focus keyphrase not found in the URL.\",\"score\":1,\"maxScore\":5,\"error\":1},\"keyphraseInIntroduction\":{\"title\":\"Focus keyphrase in introduction\",\"description\":\"Your Focus keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInSubHeadings\":{\"title\":\"Focus keyphrase in Subheadings\",\"description\":\"Your H2 and H3 subheadings reflects the topic of your copy. Good job!\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInImageAlt\":{\"title\":\"Focus keyphrase in image alt attributes\",\"description\":\"Focus keyphrase found in image alt attribute(s).\",\"score\":9,\"maxScore\":9,\"error\":0}},\"score\":83},\"additional\":[{\"keyphrase\":\"Carriage Return Line Feed\",\"score\":83,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":4},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase found in image alt attribute(s).\",\"score\":9,\"maxScore\":9,\"error\":0}}},{\"keyphrase\":\"CRLF Injection Vulnerability\",\"score\":83,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":3},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase found in image alt attribute(s).\",\"score\":9,\"maxScore\":9,\"error\":0}}},{\"keyphrase\":\"Injection Vulnerability\",\"score\":83,\"analysis\":{\"keyphraseInDescription\":{\"title\":\"Keyphrase in meta description\",\"description\":\"Keyphrase found in meta description.\",\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"title\":\"Keyphrase length\",\"description\":\"Good job!\",\"score\":9,\"maxScore\":9,\"error\":0,\"length\":2},\"keyphraseInIntroduction\":{\"title\":\"Keyphrase in introduction\",\"description\":\"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.\",\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInImageAlt\":{\"title\":\"Keyphrase in image alt attributes\",\"description\":\"Keyphrase found in image alt attribute(s).\",\"score\":9,\"maxScore\":9,\"error\":0}}}]}","primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/03\/CRLF.png","og_image_width":"1060","og_image_height":"593","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Web Application Security","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"open_ai":null,"created":"2021-10-27 15:11:40","updated":"2022-12-02 07:49:24"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/\" title=\"Vulnerability Disclosure\">Vulnerability Disclosure<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tCRLF Injection\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Vulnerability Disclosure","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/vulnerability-disclosure\/"},{"label":"CRLF Injection","link":"https:\/\/www.varutra.com\/varutravrt3\/crlf-carriage-return-line-feed-injection\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/9712"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=9712"}],"version-history":[{"count":5,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/9712\/revisions"}],"predecessor-version":[{"id":20310,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/9712\/revisions\/20310"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/9716"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=9712"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=9712"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=9712"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}