WEB CACHE DECEPTION FOR BEGINNERS!
Hi! I'm a pentester and a bug bounty hunter who's learning everyday and sharing useful resources as I move along. Subscribe to my channel because I'll be sharing my knowledge in new videos regularly. SIGN UP ON Intigriti: http://go.intigriti.com/farah BUY ME A COFFEE: https://www.buymeacoffee.com/farahhawa SOCIAL MEDIA: Follow me on Twitter: / farah_hawaa Follow me on Instagram: / farah_hawaa Connect with me on LinkedIn: / farah-hawa-a012b8162 TIME STAMPS: 00:00 Introduction 00:56 What is Cache? 01:24 Which files are cached? 01:52 Lab Demo 03:08 Path Confusion 04:06 The Bug 05:42 Attackers Exploitation 06:29 Summarizing Conditions 06:53 Instructions for the lab INSTRUCTIONS TO SET UP VARNISH WITH YOUR APP: https://linuxhint.com/varnish_cache_u... CONFIG CODE: sub vcl_recv { if (req.url ~ "^[^?]*\.(php)(\?.*)?$") { return (pass); } if (req.url ~ "^[^?]*\.(css|jpg|js|gif|png|xml|flv|gz|txt|...)(\?.*)?$") { return (hash); } } RESOURCES FOR WEB CACHE DECEPTION: https://www.blackhat.com/docs/us-17/w... https://blog.cloudflare.com/understan... https://omergil.blogspot.com/2017/02/... https://blog.takemyhand.xyz/2018/05/w... HACKERONE REPORTS: https://hackerone.com/reports/593712 https://hackerone.com/reports/397508 Video editor: https://www.fiverr.com/pixelstudios1

WEB CACHE POISONING FOR BEGINNERS + GIVEAWAY(closed)

Web Cache Deception Attack

DNS Cache Poisoning - Computerphile

DEF CON 32 - Gotta Cache ‘em all bending the rules of web cache exploitation - Martin Doyhenard

Web Cache Deception Explained | Portswigger BSCP Prep

Practical Web Cache Poisoning: Redefining 'Unexploitable'

HACKING OAuth 2.0 FOR BEGINNERS!

Gotta Cache Em All: Bending the Rules of Web Cache Exploitation

Every CREEPY Way Websites Track You Explained

Web Cache Deception Made Simple – What You Need to Know!

10 Tips For Crushing Bug Bounties in the First 12 Months

BYPASSING SAML AUTHENTICATION FOR BEGINNERS!

Web Cache Deception Attacks! | New From BlackHat 2024!

Lab: Web cache poisoning with an unkeyed header

Every Type of XSS Attack, Explained

$XX,000 Airbnb impossible XSS with 4 bypasses

Exploiting Web Cache Poisoning

Passkeys Explained: Are They Actually Better Than Passwords?

Exploiting Path Delimiters for Web Cache Deception | PortSwigger Lab | Explained

