Pass the PMP® Exam on Your First Try — Expert-Led Training
Live Online Classes in Design, Coding & AI — Small Classes, Free Retakes
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore groundbreaking web cache exploitation techniques in this 44-minute conference talk from DEF CON 32. Dive deep into two powerful new methods that leverage RFC ambiguities to circumvent traditional web cache deception and poisoning attack limitations. Learn about Static Path Deception through a detailed case study demonstrating how to compromise application confidentiality in Nginx-Cloudflare environments. Master Cache Key Confusion and its application in exploiting URL parsing inconsistencies across major platforms like Microsoft Azure Cloud, enabling arbitrary cache poisoning and denial of service attacks. Watch a live demonstration combining Cache Key Confusion with an open redirect vulnerability to achieve complete site takeover through arbitrary JavaScript code execution. Walk away with innovative exploitation techniques and a comprehensive methodology for identifying and exploiting URL and HTTP parsing discrepancies.
Syllabus
DEF CON 32 - Gotta Cache ‘em all bending the rules of web cache exploitation - Martin Doyhenard
Taught by
DEFCONConference