URL Parser & Query Parameter Inspector
Break down, analyze, and inspect any URL. View individual query string parameters, path segments, and export structured JSON.
| Parameter Key | Decoded Value | Action |
|---|
⚠️ 5 Fatal Traps in URL Parsing & Request Routing Architecture
💥 1. SSRF via Ambiguous Host Parsing (Decimal & Octal IPs)
Naive URL parser regexes that block 127.0.0.1 or localhost are trivially bypassed by alternate IP encodings. For instance, decimal 2130706433, octal 0177.0.0.1, hex 0x7f.0.0.1, or IPv6 bracket notation [::1] all resolve to localhost in operating system network stacks, allowing attackers to access internal cloud metadata services (e.g. AWS 169.254.169.254).
⚖️ 2. Protocol Confusion with Scheme-Relative URLs (//evil.com)
A URL starting with //evil.com lacks an explicit protocol scheme. Backend validation checks (e.g. url.startsWith('/')) mistakenly classify it as a safe relative internal route, but web browsers resolve it as a network-path reference that inherits the current page protocol, executing an unauthorized external redirect.
🛡️ 3. HTTP Parameter Pollution (HPP) Across Different Frameworks
When duplicate query parameters appear (e.g. ?role=user&role=admin), different backend web frameworks parse them inconsistently: Node.js Express creates an array (['user','admin']), PHP takes the last occurrence (admin), and ASP.NET joins them with commas (user,admin). This behavior divergence allows attackers to bypass Web Application Firewalls (WAFs).
🔍 4. The Browser Fragment Hash Isolation Boundary
The URL fragment identifier (anything after the # character) is handled exclusively by the browser; web browsers NEVER include it in HTTP request packets sent to servers. Authentication flows or webhook handlers that mistakenly place session tokens after the hash symbol fail completely on server-side APIs unless extracted by browser JavaScript.
🚀 5. Userinfo Impersonation & Credential Splitting (@ Symbol)
RFC 3986 allows user authentication strings before an @ character: https://trusted.bank.com@evil-site.com/. Visual users and naive substring parsers see trusted.bank.com and trust the link, while the actual connection connects to evil-site.com with username credentials. Modern browsers deprecate userinfo, but automated crawlers and microservices remain vulnerable.