Web Cache Poisoning

Web cache poisoning & deception — get a shared cache to serve attacker content to other users, or trick it into caching victims' private pages. Load behind a CDN/cache (Cloudflare, Varnish, Fastly, Akamai), on unkeyed headers, `X-Forwarded-Host`, cache headers, or static-looking URLs. Signals: `Age`/`X-Cache` headers, CDN, reflected headers.

NoorQureshi 116ed94 2.3 KB Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/web/web-cache-poisoning commit 116ed942ec

Frequently asked questions

npx skillmds@latest add noorqureshi/web-cache-poisoning