Company
Date Published
Author
Detectify
Word count
889
Language
-
Hacker News points
None

Summary

James Kettle, known for his research in web cache vulnerabilities, introduced new techniques for exploiting web cache poisoning called Web Cache Entanglement at the Black Hat USA event. This approach leverages "keyed" components, such as the Host header and request line, due to how web servers process requests, allowing attackers to manipulate caches and serve harmful responses. The methodology involves selecting a cache oracle, identifying transformations in cache key handling, and exploiting vulnerabilities through gadget chaining, which can turn reflected XSS into stored XSS or exploit dynamic content. Kettle emphasizes the overlooked security risks in web caches, urging developers to treat all vulnerabilities seriously, avoid rewriting cache keys, and patch even low-risk vulnerabilities.