Gotta cache 'em all: bending the rules of web cache exploitation
portswigger.net | research | #vulnerability-research | #web-security | #research | #cdn | #url-parsing | #cache-poisoning | #parser-discrepancies | #web-cache
Summary
Doyhenard's research exploits URL parser discrepancies and RFC ambiguities between CDNs and origins — delimiters, normalization, static extensions — achieving arbitrary cache poisoning and deception.
- Published
- Collected
Skip to content