Web Cache Poisoning: Hunting Methodology & Real-World Examples

Поділитися
Вставка
  • Опубліковано 21 лис 2024

КОМЕНТАРІ •

  • @kashif_ali6919
    @kashif_ali6919 5 днів тому +1

    voice + guidence i love that

  • @rajmaharjan5437
    @rajmaharjan5437 16 днів тому +1

    glad I found this gem :)

  • @user-tr3sh8tp9p
    @user-tr3sh8tp9p Місяць тому +1

    Great explanation. Thanks

  • @dittonachan
    @dittonachan Місяць тому +1

    great explaination, loved it.

  • @comosaycomosah
    @comosaycomosah Місяць тому +1

    well put together

  • @testauthoritytes9917
    @testauthoritytes9917 Місяць тому

    Medusa reminds me modlishka. Anyway great explanation.
    Some more points - you have worked on lazy loading cache hit and cache miss architecture that has a condition that this type if cache poisioning is only real of cache is updated.
    There are some more architecture you may want to explore, its write through and session storing.
    For write through architecture , cache cant be poisoned or updated to be delivered to multiple users for same content if you are not writing to DB.
    For session storing cached
    architecture mechanisms xss will fall short and you may want to try csrf.

    • @Medusa0xf
      @Medusa0xf  27 днів тому +2

      How about you share some articles for this on my server?

  • @H4ckerNafeed
    @H4ckerNafeed 24 дні тому +1

    The tiny note name? where u using to save payloads?

  • @senlin9414
    @senlin9414 26 днів тому +1

    Great Content, but the background shouldn't be flickering.

  • @nishantdalvi9470
    @nishantdalvi9470 Місяць тому

    Please make this sort of video for Oauth misconfiguration as well

  • @wmpdx7
    @wmpdx7 22 дні тому

    Love you 😘👌

  • @smilehackermax
    @smilehackermax Місяць тому

    Nice one!

  • @mysteriousministar2481
    @mysteriousministar2481 Місяць тому

    Nice video

  • @halfman.halfamazing3113
    @halfman.halfamazing3113 26 днів тому

    Unable to focus while stuff running on the background with distracting music, it would be better if the video is some calm or lofi stuff.

  • @Bluesurfer-w8g
    @Bluesurfer-w8g Місяць тому +6

    Ps : don't use glitch screen background when explaining something, it's uncomfortable

    • @testauthoritytes9917
      @testauthoritytes9917 Місяць тому

      How comfortable is that when you have your website hosting different image or probably your user poset is changed or someone rides csrf and transfer legit amount from your digital wallet to some of your friend that you don't know.
      Get used it if you are blue 🔵, life will be less stressful 😊

    • @pratiksawant8119
      @pratiksawant8119 Місяць тому

      Agree

    • @shouvikkundu8289
      @shouvikkundu8289 27 днів тому

      Yup it's kinda make us distract

    • @Medusa0xf
      @Medusa0xf  27 днів тому

      Okay

  • @Aquax1000
    @Aquax1000 Місяць тому +1

    Yo man hook me up with some BAC resources (not basics)

    • @Medusa0xf
      @Medusa0xf  27 днів тому +1

      You should hear this podcast.
      ua-cam.com/video/w4-_wd_ReX4/v-deo.htmlsi=hnBOCR2AioksJdFH

    • @Aquax1000
      @Aquax1000 26 днів тому

      @@Medusa0xf I hate that smile do you have any other resources where you are the only one like same as this video. I love your blog but it's very nice to see any video on that. If you don't mind Medusa I'm doing fully manual testing now including BAC,Auth and OAuth so can you tell me am I missing out on something here ?

  • @bambastala7446
    @bambastala7446 16 днів тому

    Don't use anime it's distracting