DiscoverBlack HatPractical Web Cache Poisoning: Redefining 'Unexploitable'
Practical Web Cache Poisoning: Redefining 'Unexploitable'

Practical Web Cache Poisoning: Redefining 'Unexploitable'

Update: 2018-08-28
Share

Description

Modern web applications are composed from a crude patchwork of caches and content delivery networks. In this session I'll show you how to compromise websites by using esoteric web features to turn their caches into exploit delivery systems, targeting everyone that makes the mistake of visiting their homepage.

By James Kettle

Full Abstract & Presentation Materials: https://www.blackhat.com/us-18/briefings/schedule/#practical-web-cache-poisoning-redefining-unexploitable-10200
Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Practical Web Cache Poisoning: Redefining 'Unexploitable'

Practical Web Cache Poisoning: Redefining 'Unexploitable'

Black Hat