Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up

URL Parser & Query Parameter Inspector

Break down, analyze, and inspect any URL. View individual query string parameters, path segments, and export structured JSON.

Protocol
--
Hostname
--
Port
--
Hash / Fragment
--
Pathname & Segments
--
Query Parameters (0)
Parameter Key Decoded Value Action

⚠️ 5 Fatal Traps in URL Parsing & Request Routing Architecture

💥 1. SSRF via Ambiguous Host Parsing (Decimal & Octal IPs)

Naive URL parser regexes that block 127.0.0.1 or localhost are trivially bypassed by alternate IP encodings. For instance, decimal 2130706433, octal 0177.0.0.1, hex 0x7f.0.0.1, or IPv6 bracket notation [::1] all resolve to localhost in operating system network stacks, allowing attackers to access internal cloud metadata services (e.g. AWS 169.254.169.254).

⚖️ 2. Protocol Confusion with Scheme-Relative URLs (//evil.com)

A URL starting with //evil.com lacks an explicit protocol scheme. Backend validation checks (e.g. url.startsWith('/')) mistakenly classify it as a safe relative internal route, but web browsers resolve it as a network-path reference that inherits the current page protocol, executing an unauthorized external redirect.

🛡️ 3. HTTP Parameter Pollution (HPP) Across Different Frameworks

When duplicate query parameters appear (e.g. ?role=user&role=admin), different backend web frameworks parse them inconsistently: Node.js Express creates an array (['user','admin']), PHP takes the last occurrence (admin), and ASP.NET joins them with commas (user,admin). This behavior divergence allows attackers to bypass Web Application Firewalls (WAFs).

🔍 4. The Browser Fragment Hash Isolation Boundary

The URL fragment identifier (anything after the # character) is handled exclusively by the browser; web browsers NEVER include it in HTTP request packets sent to servers. Authentication flows or webhook handlers that mistakenly place session tokens after the hash symbol fail completely on server-side APIs unless extracted by browser JavaScript.

🚀 5. Userinfo Impersonation & Credential Splitting (@ Symbol)

RFC 3986 allows user authentication strings before an @ character: https://trusted.bank.com@evil-site.com/. Visual users and naive substring parsers see trusted.bank.com and trust the link, while the actual connection connects to evil-site.com with username credentials. Modern browsers deprecate userinfo, but automated crawlers and microservices remain vulnerable.

Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement