Top 10 winner
Cached and Confused: Web Cache Deception in the Wild
Web cache deception exploits path confusion: a URL such as /account.php/nonexistent.jpg looks static to a caching proxy but resolves to a private page at the origin, so the cache stores it for any attacker to fetch. A measurement of 340 top sites found leaked personal data, session and CSRF tokens, plus five path-confusion variants that widen the attack.
Record
- Researcher
- Seyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo, Engin Kirda and William Robertson
- Published by
- USENIX
- Format
- Whitepaper
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Seyed Ali Mirheidari, Sajjad Arshad, Kaan Onarlioglu, Bruno Crispo, Engin Kirda and William Robertson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .