Later archive addition
Permanent URL Hijack Through 301 HTTP Redirect Cache Poisoning
The article shows how a network attacker can answer one clear-text HTTP request with a cacheable 301 redirect, persistently steering later browser visits to an attacker-controlled HTTPS reverse proxy. It explores cross-origin cache behavior, redirect-chain automation, and limits imposed by HSTS preload, HTTPS-first navigation, and existing cached entries.
Record
- Researcher
- Piotr Duszyński
- Published by
- duszynski.eu
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Piotr Duszyński, first published at the original source. Preserved copies are kept so the citation survives its host.