Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Web Cache Entanglement - Novel Pathways to Poisoning

Black Hat via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This session presents advanced techniques for discovering and exploiting subtle web-cache behaviors, including parameter cloaking, cache-key injection, normalization flaws, and internal cache poisoning. It also discusses testing tools and defensive mitigations.

Syllabus

Intro
Unanswered questions in cache poisoning
Outline
Recap: cache poisoning concept
Recap: Practical Web Cache Poisoning (2018) Keyed GET /research?x=1 HTTP/1.1
Methodology
Unkeyed port
Unkeyed query detection
Unkeyed query effect Hides obvious XSS from pentesters & bug bounty hunters
Redirect Dos gadget
Cache parameter cloaking: Akamai?
Parameter cloaking: Rack::Cache?
Parameter cloaking: Ruby on Rails
Dynamic resource gadget
Unkeyed method
Local redirect gadget
Cache key normalisation
Normalisation gadgets - XSS
Cache key injection - Akamai
Cache key injection - Cloudflare? Select Prote Cloudflare documentation
Application Cache Poisoning - Adobe
Blind Internal Cache Poisoning - DoD
Recognising internal cache poisoning
Param Miner
Further Reading

Taught by

Black Hat

Reviews

Start your review of Web Cache Entanglement - Novel Pathways to Poisoning

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.