Top 10 winner
Practical Web Cache Poisoning
Unkeyed request inputs such as X-Forwarded-Host or X-Original-URL change a response that a cache then stores under an ordinary key, so every later visitor is served the attacker's version. The work chains this into stored XSS, hijacked script and JSON loads, open redirects, Open Graph spoofing and cross-region CDN poisoning, and ships a Burp extension for finding unkeyed inputs.
Record
- Researcher
- James Kettle
- Published by
- PortSwigger Research
- Date
- Topic
- HTTP
In the archive
Related sources
- Param Miner
- Bypassing Web Cache Poisoning Countermeasures
- Responsible denial of service with web cache poisoning
- BSidesMCR 2018: Practical Web Cache Poisoning: Redefining 'Unexploitable' by James Kettle
- Practical Web Cache Poisoning: Redefining 'Unexploitable'
- Black Hat USA 2018 - Practical Web Cache Poisoning Redefining Unexploitable
Tags
This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .