Black Hat USA 2018

James Kettle

Practical Web Cache Poisoning: Redefining ‘Unexploitable’

Aug 2018
play

Modern web applications are composed from a crude patchwork of caches and content delivery networks. In this session I’ll show you how to compromise websites by using esoteric web features to turn their caches into exploit delivery systems, targeting everyone that makes the mistake of visiting their homepage.

Discuss

0 comment