The Most Addictive Python and SQL Courses
Build the Finance Skills That Lead to Promotions, Not Just Certificates
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course presents practical methods for detecting, exploiting, and defending against server-side web cache poisoning. It covers cache keys, unkeyed inputs, selective poisoning, exploit chaining, resource hijacking, and defenses through demonstrations on real-world web applications and infrastructure.
Syllabus
Intro
Param Miner
Outline
Caching Threat Landscape
Cache poisoning objective
Cache keys
Cache key collisions
Cache Poisoning Methodology
Trusting headers
Unkeyed input detection
Explore and Inject
Seizing the Cache
Selective poisoning
DOM Poisoning
Mystery Interaction
Mozilla SHIELD
Chaining Unkeyed Inputs
Hidden Route Poisoning
Resource Hijacking
Open Graph hijacking
Cross-Cloud Poisoning: Cloudflare
Beyond fake hosts
External cache poison (1/3)
Internal cache poison (2/3)
Drupal Open redirect (3/3)
Combining ingredients
Defense
Takeaways
Taught by
Black Hat