HTTP parameter pollution
SkillAI & modelsSend the same parameter more than once so the WAF/validator and the backend disagree on which value wins, bypassing filters, access control, or business logic. Load on "HPP", when a value is validated at one layer but used at another, or when a WAF blocks a payload you need to slip past. Signals: proxies/gateways in front of the app, duplicated params reflected inconsistently.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the HTTP parameter pollution skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/web/web-http-parameter-pollution/SKILL.md and read by ahel’s review.
When it applies
A request passes through more than one component that parses parameters — a WAF/gateway, then the app; or a frontend that builds a backend request. If they resolve a duplicated parameter differently, you can show one value to the guard and another to the logic.
Why it works
There is no single rule for ?x=a&x=b: PHP/Apache take the last, ASP/IIS concatenates
(a,b), classic JSP takes the first, Node/Express makes an array. When the validator and
the consumer sit on different stacks, a value that passes validation isn't the value that's used.
Method
- Map the parsing: send
?p=1&p=2(and body dups) and observe which value the response reflects or acts on — that tells you first/last/concat/array. - Split a blocked payload: if a WAF blocks
q=<svg onload=..>, tryq=<svg&q=onload=..>where the backend concatenates — the signature never appears whole to the WAF. - Override server-side params: append your own copy of a param the app also sets internally
(e.g.
role,amount,redirect_uri) so your last-wins value overrides the trusted one. - Access control / logic: pollute IDs or flags where the auth check reads one occurrence and the data layer reads another.
- Client-side HPP: when a link/form is built from your input, inject
&-encoded params to add fields to the generated request.
Gotchas
- Behaviour is stack-specific — always confirm the parsing empirically before relying on it.
- Body vs query vs path params may parse differently in the same app; test each channel.
- Concatenation (
a,b) can corrupt the payload — order the duplicates to land valid syntax.
Verify success
The duplicated parameter produces a different outcome than the single one — a filter is bypassed, an internal value overridden, or a logic/authz decision changes — reproducibly.
References
OWASP Testing Guide (HPP); PortSwigger notes on parameter parsing; framework parameter-precedence tables.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
web-http-parameter-pollution- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · michtio
The pick for PHPfeature-flags-php
Skill · posthog
The pick for PHPowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)skill-creator
Skill · anthropics
More in AI & modelswayfinder
Skill · mattpocock
More in AI & models