Black Hat USA 2018 - Practical Web Cache Poisoning Redefining Unexploitable @HackersOnBoard
Black Hat USA 2018 - Practical Web Cache Poisoning Redefining Unexploitable  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 4 days ago
Modern web applications are composed from a crude patchwork of caches and content delivery networks. In this session I'll show you how to compromise websites by using esoteric web features to turn their caches into exploit delivery systems, targeting everyone that makes the mistake of visiting their homepage.

I'll illustrate and develop this technique with vulnerabilities that handed me control over numerous well known websites and frameworks, progressing from simple single-request attacks to intricate exploit chains that hijack JavaScript, pivot across cache layers, subvert social media and misdirect cloud services in pursuit of the perfect exploit.

Unlike previous cache poisoning techniques, this approach doesn't rely on other vulnerabilities like response splitting, or cache-server quirks that are easily patched away. Instead, it exploits core principles of caching, and as such affects caching solutions indiscriminately. The repercussions also extend beyond websites - I'll show how using this approach, I was able to compromise Mozilla infrastructure and partially hijack a notorious Firefox feature, letting me conduct tens of millions of Firefox browsers as my personal low-fat botnet.

In addition to sharing a thorough detection methodology, I'll also release and open source the Burp Suite Community extension that fueled this research. You'll leave with an altered perspective on web exploitation, and an appreciation that the simple act of placing a cache in front of a website can take it from completely secure to critically vulnerable.
Black Hat USA 2018 - Practical Web Cache Poisoning Redefining UnexploitableBlack Hat USA 2018 - Automated Discovery of Deserialization Gadget ChainsBlack Hat USA 2018 - Back to the Future A Radical Insecure Design of KVM on ARMBlack Hat USA 2018 - AFLs Blindspot and How to Resist AFL Fuzzing for Arbitrary ELF BinariesBlack Hat USA 2018 - DeepLocker - Concealing Targeted Attacks with AI LocksmithingDEF CON 27 - Bill Swearingen - HAKC THE POLICEDEF CON 27 - Breaking The Back End It Is Not Always A Bug Sometimes It Is Just Bad DesignDEF CON 27 - 100 Seconds of Solitude Defeating Cisco Trust Anchor With FPGA Bitstream ShenanigansDEF CON 27 - Panel - DEF CON to help hackers anonymously submit bugs to the government discussDEF CON 27 - Alvaro Munoz - SSO Wars The Token MenaceBlack Hat USA 2018 - Fire & Ice Making and Breaking macOS FirewallsDEF CON 27 - smea - Adventures In Smart Buttplug Penetration testing
HackersOnBoard |

Black Hat USA 2018 - Practical Web Cache Poisoning Redefining Unexploitable

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER