Web Hack List

Later archive addition

Permanent URL Hijack Through 301 HTTP Redirect Cache Poisoning

The article shows how a network attacker can answer one clear-text HTTP request with a cacheable 301 redirect, persistently steering later browser visits to an attacker-controlled HTTPS reverse proxy. It explores cross-origin cache behavior, redirect-chain automation, and limits imposed by HSTS preload, HTTPS-first navigation, and existing cached entries.

Record

Researcher
Piotr Duszyński
Published by
duszynski.eu
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Piotr Duszyński, first published at the original source. Preserved copies are kept so the citation survives its host.