Web Cache Poisoning: Hunting Methodology & Real-World Examples

Поділитися
Вставка
  • Опубліковано 9 лют 2025
  • This video explores the Web Cache Poisoning vulnerability in detail. We'll cover essential concepts such as web caching, cache keys, cache hits, cache misses, and cache busters. You’ll also learn how to identify this vulnerability in web applications, complete with practical examples. By the end of the video, you’ll have a comprehensive understanding of all the key concepts related to web cache poisoning.
    .
    .
    .
    Blogs: / medusa0xf
    .
    .
    .
    Social media:
    Twitter: / medusa_0xf
    .
    .
    .
    Discord: / discord
    .
    .
    HackerOne Report
    hackerone.com/...
    .
    .
    .
    Introduction: 0:00
    Caching: 0:26
    CDN Caching [Cache Miss & Hit]: 0:44
    Cache Key: 1:28
    Recon: 2:17
    Web Cache Poisoning: 3:00
    Cache Buster: 4:28
    Unkeyed & Keyed Input: 5:12
    Hunting Methodology: 7:30
    HackerOne Report: 9:38
    Ending: 11:07
    .
    .
    Like and Subscribe :)
    .
    .
    Music: Karl Casey @ White Bat Audio
    #api #owasp #portswigger #bugbounty #bola #postman #pentesting #api #hack #bola #tryhackme #hackerone #apihacking #computerscience #javascript #python #postman #ctf #bughunting #pentesting #hacking #hackingtools #burpsuite #portswigger #ethicalhacking #OAuth #webhacking #programming #websecurity #technology #practical #artificialintelligence #web #recon #bypass

КОМЕНТАРІ • 50

  • @GreatAllen-p4m
    @GreatAllen-p4m 24 дні тому

    love ur style plz stay consitent w uploads and ur voice is fyer

    • @Medusa0xf
      @Medusa0xf  12 днів тому

      Thank you, I'll try my best to keep things consistent!

  • @user-tr3sh8tp9p
    @user-tr3sh8tp9p 3 місяці тому +1

    Great explanation. Thanks

  • @haanrey
    @haanrey Місяць тому

    VERY GOOD EXPLANATION VIDEO . thanks for explaining it so nicely and so patiently and with example . thank you . i love your videos .

    • @Medusa0xf
      @Medusa0xf  Місяць тому

      Thanks a lot, it took effort!

  • @Allstuffchannel01
    @Allstuffchannel01 2 місяці тому +1

    voice + guidence i love that

  • @rajdotone
    @rajdotone 3 місяці тому +1

    glad I found this gem :)

  • @rlsn-kali
    @rlsn-kali Місяць тому

    great explanation

    • @Medusa0xf
      @Medusa0xf  12 днів тому

      I'm glad you liked it.

  • @comosaycomosah
    @comosaycomosah 3 місяці тому +1

    well put together

    • @Medusa0xf
      @Medusa0xf  3 місяці тому +1

      Glad you liked it!

  • @dittonachan
    @dittonachan 3 місяці тому +1

    great explaination, loved it.

  • @abhishek_k7
    @abhishek_k7 21 день тому

    1. flickering animations can cause epileptic episodes in some people. they are also kinda annoying (imo).
    2. anime scenes are very distracting when learning something.
    but content & coverage is good! I know you are experimenting but I just wanted to leave some feedback since this seems like a nice channel to learn stuff.

    • @Medusa0xf
      @Medusa0xf  12 днів тому +1

      Thanks for the feedback

  • @smilehackermax
    @smilehackermax 3 місяці тому

    Nice one!

  • @testauthoritytes9917
    @testauthoritytes9917 3 місяці тому +1

    Medusa reminds me modlishka. Anyway great explanation.
    Some more points - you have worked on lazy loading cache hit and cache miss architecture that has a condition that this type if cache poisioning is only real of cache is updated.
    There are some more architecture you may want to explore, its write through and session storing.
    For write through architecture , cache cant be poisoned or updated to be delivered to multiple users for same content if you are not writing to DB.
    For session storing cached
    architecture mechanisms xss will fall short and you may want to try csrf.

    • @Medusa0xf
      @Medusa0xf  3 місяці тому +2

      How about you share some articles for this on my server?

  • @wmpdx7
    @wmpdx7 3 місяці тому

    Love you 😘👌

  • @Hreem298
    @Hreem298 Місяць тому

    What is Lucky13 vulnerability and side channel attack=>bit flip

  • @Kalyan-os8st
    @Kalyan-os8st 2 місяці тому

    Great Explanation, Is there any chances explaning for HTTP Request Smuggling will be helpful

  • @senlin9414
    @senlin9414 3 місяці тому +2

    Great Content, but the background shouldn't be flickering.

    • @Medusa0xf
      @Medusa0xf  3 місяці тому

      Thanks for the tip

  • @Bluesurfer-w8g
    @Bluesurfer-w8g 3 місяці тому +9

    Ps : don't use glitch screen background when explaining something, it's uncomfortable

    • @testauthoritytes9917
      @testauthoritytes9917 3 місяці тому

      How comfortable is that when you have your website hosting different image or probably your user poset is changed or someone rides csrf and transfer legit amount from your digital wallet to some of your friend that you don't know.
      Get used it if you are blue 🔵, life will be less stressful 😊

    • @pratiksawant8119
      @pratiksawant8119 3 місяці тому +1

      Agree

    • @shouvikkundu8289
      @shouvikkundu8289 3 місяці тому +1

      Yup it's kinda make us distract

    • @Medusa0xf
      @Medusa0xf  3 місяці тому

      Okay

  • @nishantdalvi9470
    @nishantdalvi9470 3 місяці тому

    Please make this sort of video for Oauth misconfiguration as well

  • @mysteriousministar2481
    @mysteriousministar2481 3 місяці тому

    Nice video

  • @H4ckerNafeed
    @H4ckerNafeed 3 місяці тому +1

    The tiny note name? where u using to save payloads?

    • @Medusa0xf
      @Medusa0xf  2 дні тому

      i used online code snippets.

  • @unknown9860
    @unknown9860 Місяць тому

    Medusa how about live hunting?

  • @halfman.halfamazing3113
    @halfman.halfamazing3113 3 місяці тому +1

    Unable to focus while stuff running on the background with distracting music, it would be better if the video is some calm or lofi stuff.

    • @Medusa0xf
      @Medusa0xf  2 місяці тому

      Yeah i've been experimenting with editing. Check out the new video, you will love it!

  • @b4dboy_17
    @b4dboy_17 10 днів тому

    what's the anime name themed here? :)

    • @Medusa0xf
      @Medusa0xf  2 дні тому

      Solo leveling and jujutsu Kaisan

  • @Aquax1000
    @Aquax1000 3 місяці тому +1

    Yo man hook me up with some BAC resources (not basics)

    • @Medusa0xf
      @Medusa0xf  3 місяці тому +1

      You should hear this podcast.
      ua-cam.com/video/w4-_wd_ReX4/v-deo.htmlsi=hnBOCR2AioksJdFH

    • @Aquax1000
      @Aquax1000 3 місяці тому

      @@Medusa0xf I hate that smile do you have any other resources where you are the only one like same as this video. I love your blog but it's very nice to see any video on that. If you don't mind Medusa I'm doing fully manual testing now including BAC,Auth and OAuth so can you tell me am I missing out on something here ?

  • @bambastala7446
    @bambastala7446 3 місяці тому +1

    Don't use anime it's distracting

    • @Medusa0xf
      @Medusa0xf  Місяць тому

      Yeah, I don’t usually use it. I’m just experimenting with new ideas and noting feedback. Thank you!