Lab: Web cache poisoning with an unkeyed header

Описание к видео Lab: Web cache poisoning with an unkeyed header

In-depth solution to PortSwigger's "Web cache poisoning with an unkeyed header" lab.

👀 Check out playlist    • Web Cache Poisoning   for all my solutions to the Web Cache Poisoning labs from PortSwigger.

Try it yourself:
https://portswigger.net/web-security/...

Timestamps:
00:00 - Intro
00:13 - Identify a suitable cache oracle
01:20 - Add a cache buster
02:13 - When are two requests identical?
03:12 - Why do we add a cache buster?
03:53 - Test the cache buster in Burp
04:37 - Use Param Miner to find X-Forwarded-Host header
05:28 - What is an unkeyed input?
06:18 - Inject the X-Forwarded-Host header

Комментарии

Информация по комментариям в разработке