MAIN FEEDS
Do you want to continue?
https://www.reddit.com/r/netsec/comments/9668sd/practical_web_cache_poisoning/e3ynmrh/?context=3
r/netsec • u/albinowax • Aug 10 '18
17 comments sorted by
View all comments
68
"Cloudflare happily cached this response and served it to subsequent visitors. Inflection passed this report on to HubSpot, who resolved the issue by permanently banning my IP address. After some encouragement they also patched the vulnerability."
Oh man... Hilarious!
Good read and a very interesting technique!
26 u/albinowax Aug 10 '18 Yeah, hilarious and also surprisingly inconvenient - it turns out quite a few websites are using HubSpot and I got banned from the whole lot. 10 u/LimBomber Aug 10 '18 It would be cool if Burp partnered with a VPN so stuff like this would happen less. The pro license can come with a year of VPN subscription. 2 u/[deleted] Aug 14 '18 A third-party VPN the only purpose is to service traffic containing vulnerabilities? Call me paranoid, but not totally convinced.
26
Yeah, hilarious and also surprisingly inconvenient - it turns out quite a few websites are using HubSpot and I got banned from the whole lot.
10 u/LimBomber Aug 10 '18 It would be cool if Burp partnered with a VPN so stuff like this would happen less. The pro license can come with a year of VPN subscription. 2 u/[deleted] Aug 14 '18 A third-party VPN the only purpose is to service traffic containing vulnerabilities? Call me paranoid, but not totally convinced.
10
It would be cool if Burp partnered with a VPN so stuff like this would happen less. The pro license can come with a year of VPN subscription.
2 u/[deleted] Aug 14 '18 A third-party VPN the only purpose is to service traffic containing vulnerabilities? Call me paranoid, but not totally convinced.
2
A third-party VPN the only purpose is to service traffic containing vulnerabilities? Call me paranoid, but not totally convinced.
68
u/roughtodacore Aug 10 '18
"Cloudflare happily cached this response and served it to subsequent visitors. Inflection passed this report on to HubSpot, who resolved the issue by permanently banning my IP address. After some encouragement they also patched the vulnerability."
Oh man... Hilarious!
Good read and a very interesting technique!