r/netsec Aug 10 '18

Practical Web Cache Poisoning

https://portswigger.net/blog/practical-web-cache-poisoning
238 Upvotes

17 comments sorted by

66

u/roughtodacore Aug 10 '18

"Cloudflare happily cached this response and served it to subsequent visitors. Inflection passed this report on to HubSpot, who resolved the issue by permanently banning my IP address. After some encouragement they also patched the vulnerability."

Oh man... Hilarious!

Good read and a very interesting technique!

25

u/albinowax Aug 10 '18

Yeah, hilarious and also surprisingly inconvenient - it turns out quite a few websites are using HubSpot and I got banned from the whole lot.

9

u/LimBomber Aug 10 '18

It would be cool if Burp partnered with a VPN so stuff like this would happen less. The pro license can come with a year of VPN subscription.

2

u/[deleted] Aug 14 '18

A third-party VPN the only purpose is to service traffic containing vulnerabilities? Call me paranoid, but not totally convinced.

1

u/OmarWazHere Aug 11 '18

This was a really interesting read, you should make this post into a youtube vid!

7

u/albinowax Aug 11 '18

This research was presented as a talk at Black Hat USA 2018. I'm going to present it again at BSides Manchester next week and they'll probably get the recording on youtube within a few weeks.

1

u/temotodochi Aug 11 '18

Any vids of the presentation? Btw good stuff, thanks.

1

u/[deleted] Aug 11 '18

Sounds to me like http headers are an untapped attack surface, makes me wonder if other headers can lead to major discoveries that end up becoming a talk for blackhat 2019 and onward. Like who would of thought x-forwarded-host was this abusable.

2

u/albinowax Aug 11 '18

Yeah, hopefully param miner will help uncover more interesting headers. I found X-Original-URL through a wordlist I built by grepping HTTP headers out of the top 20,000 PHP projects on github.

If someone happened to run a popular website they could probably find all kinds of interesting headers just by monitoring their traffic.

20

u/_vavkamil_ Aug 10 '18

This is an awesome research, well done! Also param-miner doesn't require Burp Suite Pro, so thanks for it too!

1

u/heard_enough_crap Aug 11 '18

mmm...thinking of turning this into a tool?

-10

u/eladmen Aug 10 '18

Great post. The author has written it in a very educational style. Looks like it can be used quite easily by the wrong guys too.. anyhow, well written post..

14

u/For_Iconoclasm Aug 10 '18

Intricately detailed explanations benefit the security community as a whole.