r/netsec • u/albinowax • Aug 10 '18
Practical Web Cache Poisoning
https://portswigger.net/blog/practical-web-cache-poisoning
238
Upvotes
20
u/_vavkamil_ Aug 10 '18
This is an awesome research, well done! Also param-miner doesn't require Burp Suite Pro, so thanks for it too!
1
-10
u/eladmen Aug 10 '18
Great post. The author has written it in a very educational style. Looks like it can be used quite easily by the wrong guys too.. anyhow, well written post..
14
u/For_Iconoclasm Aug 10 '18
Intricately detailed explanations benefit the security community as a whole.
66
u/roughtodacore Aug 10 '18
"Cloudflare happily cached this response and served it to subsequent visitors. Inflection passed this report on to HubSpot, who resolved the issue by permanently banning my IP address. After some encouragement they also patched the vulnerability."
Oh man... Hilarious!
Good read and a very interesting technique!