Web Hack List

Top 10 winner

Cached and Confused: Web Cache Deception in the Wild

Web cache deception exploits path confusion: a URL such as /account.php/nonexistent.jpg looks static to a caching proxy but resolves to a private page at the origin, so the cache stores it for any attacker to fetch. A measurement of 340 top sites found leaked personal data, session and CSRF tokens, plus five path-confusion variants that widen the attack.

Record

Researcher
Seyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo, Engin Kirda and William Robertson
Published by
USENIX
Format
Whitepaper
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Seyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo, Engin Kirda and William Robertson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .