Back to directory
WRITEUP #5421

Web Cache Deception to API endpoint attack using cached token header

OtherWeb cache deception
by@kunalp94(Kunal pandey)
Bounty
250
Program
-
Published
Apr 13, 2019
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/@kunal94/web-cache-deception-to-api-endpoint-attack-using-cached-token-header-b01a604a5ccd
RELATED WRITEUPS
Gotta cache 'em all: bending the rules of web cache exploitation
OtherWeb cache poisoning
Splitting the email atom: exploiting parsers to bypass access controls
OtherWeb cache poisoning
Data Theft in Salesforce: Manipulating Public Links
OtherSOQL injection
When Certificates Fail: A Story of Bypassed MFA in Remote Access
Other2FA / MFA bypass
SSTI in Bug Bounty Program: The Time I Played with Handlebars and Broke Stuff
OtherSSTI

Built with ❤️ by Shubham Rawat