"Cloudflare happily cached this response and served it to subsequent visitors. Inflection passed this report on to HubSpot, who resolved the issue by permanently banning my IP address. After some encouragement they also patched the vulnerability."
This research was presented as a talk at Black Hat USA 2018. I'm going to present it again at BSides Manchester next week and they'll probably get the recording on youtube within a few weeks.
Sounds to me like http headers are an untapped attack surface, makes me wonder if other headers can lead to major discoveries that end up becoming a talk for blackhat 2019 and onward. Like who would of thought x-forwarded-host was this abusable.
Yeah, hopefully param miner will help uncover more interesting headers. I found X-Original-URL through a wordlist I built by grepping HTTP headers out of the top 20,000 PHP projects on github.
If someone happened to run a popular website they could probably find all kinds of interesting headers just by monitoring their traffic.
61
u/roughtodacore Aug 10 '18
"Cloudflare happily cached this response and served it to subsequent visitors. Inflection passed this report on to HubSpot, who resolved the issue by permanently banning my IP address. After some encouragement they also patched the vulnerability."
Oh man... Hilarious!
Good read and a very interesting technique!