cybersecurity · intermediate · ~15 min · safe pentest lab
Eliminate HTTP response splitting by stripping CRLF injection sequences from header values.
HTTP Response Splitting occurs when user input containing \r\n (CRLF) is included in an outgoing HTTP response header. An attacker can inject arbitrary headers (e.g. Set-Cookie: admin=1) or inject an entire rogue response body.
Implement:
int sanitize_header_value(const char *val, char *out, size_t out_cap);
Strip \r and \n characters from val, outputting a clean single-line header.
val == NULL, out == NULL, or out_cap == 0, return -1.\r (0x0D) and \n (0x0A) from val.out.out_cap - 1, return -1.char out[64];
sanitize_header_value("user\r\nSet-Cookie: admin=1", out, sizeof out); // returns 2, out = "userSet-Cookie: admin=1"
sanitize_header_value("clean_val", out, sizeof out); // returns 0, out = "clean_val"
val: untrusted header value; out: destination buffer; out_cap: capacity of out buffer.
Returns count of stripped CRLF characters on success, or -1 on error/overflow.
C11 freestanding. Never write past out_cap.
#include <stddef.h>
/* Strip \r and \n characters from val into out (capacity out_cap).
Return count of stripped CRLF characters on success, or -1 on invalid inputs
or if the result does not fit in out_cap. */
int sanitize_header_value(const char *val, char *out, size_t out_cap) {
(void)val; (void)out; (void)out_cap;
return -1;
}
Forgetting to NUL-terminate out; returning -1 when 0 characters are stripped; off-by-one capacity check.
val with no CRLF returns 0; val composed solely of CRLF returns count and empty string out; out_cap too small returns -1.
Solve this exercise in the browser editor — compile and run against the test harness, no setup required.