Web Cache Deception

Trick a CDN/cache into storing a victim's authenticated response at a public URL, then read it. Load on "web cache deception", when a CDN/cache sits in front of an app that serves per-user content, or to test whether private pages can be cached. Signals: `X-Cache`/`CF-Cache-Status` headers, caching by file extension, static-looking suffixes on dynamic endpoints.

NoorQureshi 1fe181d 2.5 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-cache-deception commit 1fe181d443

Frequently asked questions

npx skillmds@latest add noorqureshi/web-cache-deception