Skip to content

northsidehacker/40x

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

40x.sh — HTTP 40X Bypass Tool

A fast, modular Bash tool for testing HTTP 40X access control bypasses during web application security assessments and bug bounty hunting.


Features

  • HTTP Method Tampering — tests 35+ standard and WebDAV verbs, plus method-override headers
  • Verb Case Switching — lowercase, mixed-case, and padded method variants
  • URL Path Manipulation — encoding, double-encoding, dot traversals, semicolon tricks, extension spoofing, slash variations, and more
  • Path Case Switching — upper, lower, mixed-case, and hex-encoded paths
  • Midpath Traversal Injection — inserts traversal sequences between path segments
  • Midpath Injection at Every Slash — injects bypass sequences at every / in multi-segment paths
  • Header Bypass — IP spoofing, URL override, host tricks, proto/port/scheme spoofing headers (100+ headers)
  • Unicode Normalization Bypass — fullwidth slash (%ef%bc%8f) tricks that exploit Nginx/backend decoding mismatches
  • Trim Inconsistency Bypass — appends control characters that some parsers trim and others don't
  • Large Body Bypass — sends an 8KB padded POST body to evade WAF inspection
  • Path-as-Full-URL — injects a full URL (scheme/host/port) into the path itself
  • HTTP Version Switching — tests HTTP/1.0, HTTP/1.1, and HTTP/2
  • Baseline Calibration — auto-detects the target's 404 fingerprint to suppress false positives
  • Deduplication — skips identical request permutations
  • Curl Replay Commands — every HTTP 200 result gets a ready-to-run curl command printed in the summary for easy reproduction
  • Proxy Support — route traffic through Burp Suite or any HTTP proxy
  • Output File — tee results to a file for later review

Requirements

  • bash 4.0+
  • curl
  • bc (for millisecond delay support)

Usage

./40x.sh [options] <base_url> <path>

Options

Flag Description Default
-d <ms> Delay between requests (milliseconds) 0
-x <proxy> Proxy URL none
-t <sec> Request timeout (seconds) 5
-T <bytes> Baseline size tolerance (bytes) 50
-o <file> Save results to output file none
-h Show help

Examples

# Basic scan
./40x.sh https://example.com admin

# With Burp Suite proxy
./40x.sh -x http://127.0.0.1:8080 https://example.com api/v1/admin

# With rate limiting and output file
./40x.sh -d 200 -o results.txt https://example.com secret

# Nested path
./40x.sh https://example.com dashboard/settings

Note: A full run against a multi-segment path can generate 300–400+ requests due to the expanded technique coverage. Use -d to rate-limit against production targets or sensitive WAFs.


Techniques

Method Bypass

Tests 35+ methods including standard verbs (GET, POST, PUT, DELETE), WebDAV verbs (PROPFIND, MKCOL, LOCK, COPY, MOVE), and invented verbs (POUET, QUERY) that may bypass naive ACL checks. Also tests method-override headers (X-HTTP-Method-Override, X-Method-Override, X-Method, X-HTTP-Method) for every method, catching frameworks that tunnel verbs over POST.

Verb Case Switching

Tests case variations like get, Get, gEt, GET , and GET to exploit case-insensitive routing mismatches.

URL Bypass

Covers encoding tricks (%2e, %2f, %252f), dot traversals (./, ../), semicolon injection, whitespace padding (%20, %09, %00), extension spoofing (.php, .html, .json), and query/fragment tricks.

Path Case Switching

Tests UPPERCASE, lowercase, MiXeDcAsE, and fully hex-encoded paths to exploit case-folding inconsistencies between reverse proxies and backends.

Midpath Traversal

Injects traversal sequences (., ..;/, %2e, ;/, %09, etc.) between path segments to confuse path normalization layers.

Midpath Injection at Every Slash

Goes further than basic midpath traversal by injecting bypass sequences (./, ../, ;/, %2e/, ..;/, */, #/, etc.) at every / in the path, not just the first segment boundary — useful for deeply nested routes like /api/v1/admin/users.

Header Bypass

Tests 100+ headers including:

  • IP spoofing: X-Forwarded-For, X-Real-IP, X-Client-IP, True-Client-IP, CF-Connecting-IP, Fastly-Client-IP, X-Azure-ClientIP, Incap-Client-IP, etc.
  • URL override: X-Original-URL, X-Rewrite-URL, X-Override-URL
  • Host override: Host: localhost, Host: 127.0.0.1
  • Proto/scheme spoofing: X-Forwarded-Proto, X-Forwarded-Scheme, CloudFront-Forwarded-Proto, Front-End-Https
  • Port spoofing: X-Forwarded-Port, Cdn-Server-Port, X-Cdn-Src-Port, X-Port

Unicode Normalization Bypass

Injects the fullwidth solidus (%ef%bc%8f) before the last path segment and at path boundaries. Some reverse proxies (e.g. Nginx) normalize this differently than the backend application, creating a routing mismatch.

Trim Inconsistency Bypass

Appends percent-encoded control characters (%09, %0A, %0D, %1C%1F, %85, %A0) that some HTTP parsers strip during path normalization while others don't — exploiting the mismatch between proxy and backend trimming behavior.

Large Body Bypass

Sends a POST request with an 8KB body of padding to the target path. Some WAFs skip deep inspection on large request bodies, allowing the request through where a small one would be blocked.

Path-as-Full-URL

Embeds a full URL (scheme://host:port/path) directly into the request path across multiple schemes (http, https, ftp, webdav) and common ports, testing for proxy parsers that misinterpret an absolute URI in the path component.

HTTP Version Switching

Forces HTTP/1.0, HTTP/1.1, and HTTP/2 to surface version-specific routing or ACL differences.


Output

Results are color-coded in the terminal:

Color Meaning
🟢 Green HTTP 200 — likely bypass
🟡 Yellow HTTP 301/302 — redirect (investigate)
🔴 Red Other non-baseline response

A summary of all interesting results is printed at the end. For every HTTP 200 found, a ready-to-use curl replay command is generated and listed separately, so you can immediately re-test or hand it off to Burp Repeater without manually reconstructing the request.


False Positive Reduction

On startup, the tool sends 3 requests to random paths on the target to fingerprint the baseline 404 response (status code + body size). Any result matching that fingerprint within ±TOLERANCE bytes is automatically suppressed.

Tune sensitivity with -T <bytes> if the target has inconsistent 404 body sizes.


Disclaimer

This tool is intended for authorized security testing only. Only use it against systems you own or have explicit written permission to test. Unauthorized use may violate computer fraud laws.

About

A fast, modular Bash tool for testing HTTP 40X access control bypasses during web application security assessments and bug bounty hunting.

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages