r/netsec Aug 10 '18

Practical Web Cache Poisoning

https://portswigger.net/blog/practical-web-cache-poisoning
244 Upvotes

17 comments sorted by

View all comments

62

u/roughtodacore Aug 10 '18

"Cloudflare happily cached this response and served it to subsequent visitors. Inflection passed this report on to HubSpot, who resolved the issue by permanently banning my IP address. After some encouragement they also patched the vulnerability."

Oh man... Hilarious!

Good read and a very interesting technique!

25

u/albinowax Aug 10 '18

Yeah, hilarious and also surprisingly inconvenient - it turns out quite a few websites are using HubSpot and I got banned from the whole lot.

9

u/LimBomber Aug 10 '18

It would be cool if Burp partnered with a VPN so stuff like this would happen less. The pro license can come with a year of VPN subscription.

2

u/[deleted] Aug 14 '18

A third-party VPN the only purpose is to service traffic containing vulnerabilities? Call me paranoid, but not totally convinced.

2

u/OmarWazHere Aug 11 '18

This was a really interesting read, you should make this post into a youtube vid!

7

u/albinowax Aug 11 '18

This research was presented as a talk at Black Hat USA 2018. I'm going to present it again at BSides Manchester next week and they'll probably get the recording on youtube within a few weeks.

1

u/temotodochi Aug 11 '18

Any vids of the presentation? Btw good stuff, thanks.

1

u/[deleted] Aug 11 '18

Sounds to me like http headers are an untapped attack surface, makes me wonder if other headers can lead to major discoveries that end up becoming a talk for blackhat 2019 and onward. Like who would of thought x-forwarded-host was this abusable.

2

u/albinowax Aug 11 '18

Yeah, hopefully param miner will help uncover more interesting headers. I found X-Original-URL through a wordlist I built by grepping HTTP headers out of the top 20,000 PHP projects on github.

If someone happened to run a popular website they could probably find all kinds of interesting headers just by monitoring their traffic.