Web Cache Exploitation: Advanced Techniques for Static Path Deception and Cache Key Confusion
Get 20% off all career paths from fullstack to AI
NY State-Licensed Certificates in Design, Coding & AI — Online
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Learn advanced web cache exploitation techniques in this 36-minute Black Hat conference presentation that introduces powerful new methods for bypassing security limitations. Explore Static Path Deception and discover how to compromise application confidentiality in environments using Nginx behind Cloudflare and Apache behind CloudFront with default configurations. Master Cache Key Confusion to exploit URL parsing inconsistencies in major platforms like Microsoft Azure Cloud, enabling arbitrary cache poisoning and denial of service capabilities in OpenAI and other platforms. Watch a live demonstration combining Cache Key Confusion with an open redirect vulnerability to execute cross-domain JavaScript code by modifying static file responses. Gain access to an open-source vulnerability detection tool and hands-on lab environment to practice cache exploitation techniques while learning a comprehensive methodology for identifying and exploiting URL and HTTP parsing discrepancies.
Syllabus
Gotta Cache Em All: Bending the Rules of Web Cache Exploitation
Taught by
Black Hat