Payload class · parser-boundary

HTTP Parameter Pollution Canaries

Paired duplicate-parameter probes for comparing client, proxy, framework, validation, and business-logic interpretation. Use controlled values and change one dimension at a time.

hppduplicate-parametersparserproxybusiness-logic
Stable IDpayload:http-parameter-pollution-canariesSource record dateHuman reviewNot recordedProvenanceSource-linked

Use as a detection primitive

Paired duplicate-parameter probes for comparing client, proxy, framework, validation, and business-logic interpretation. Use controlled values and change one dimension at a time.

Do not copy blind

Identify the parser, sink, encoding, and expected non-vulnerable behavior before choosing a sample. Prefer non-destructive markers.

Recorded payloads

Detection sampleAuthorization required

Confirm the sink and encoding context before use.

?role=member&role=member-control
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

?amount=1&amount=2
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

?item=alpha&item=beta
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

?filter=one%26filter%3Dtwo
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

?id=known-controlled&id=nonexistent-control
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.

Attribution

Open the primary collection ↗

Version history: normalized permanent page created 2026-08-20.