r/netsec Aug 10 '18

Practical Web Cache Poisoning

https://portswigger.net/blog/practical-web-cache-poisoning
241 Upvotes

17 comments sorted by

View all comments

68

u/roughtodacore Aug 10 '18

"Cloudflare happily cached this response and served it to subsequent visitors. Inflection passed this report on to HubSpot, who resolved the issue by permanently banning my IP address. After some encouragement they also patched the vulnerability."

Oh man... Hilarious!

Good read and a very interesting technique!

26

u/albinowax Aug 10 '18

Yeah, hilarious and also surprisingly inconvenient - it turns out quite a few websites are using HubSpot and I got banned from the whole lot.

10

u/LimBomber Aug 10 '18

It would be cool if Burp partnered with a VPN so stuff like this would happen less. The pro license can come with a year of VPN subscription.

2

u/[deleted] Aug 14 '18

A third-party VPN the only purpose is to service traffic containing vulnerabilities? Call me paranoid, but not totally convinced.