Web Cache Poisoning: Hunting Methodology & Real-World Examples

  Рет қаралды 3,784

Medusa

Medusa

Күн бұрын

Пікірлер: 31
@kashif_ali6919
@kashif_ali6919 6 күн бұрын
voice + guidence i love that
@rajmaharjan5437
@rajmaharjan5437 17 күн бұрын
glad I found this gem :)
@Medusa0xf
@Medusa0xf 15 күн бұрын
Thanks!
@user-tr3sh8tp9p
@user-tr3sh8tp9p Ай бұрын
Great explanation. Thanks
@comosaycomosah
@comosaycomosah Ай бұрын
well put together
@Medusa0xf
@Medusa0xf 27 күн бұрын
Glad you liked it!
@dittonachan
@dittonachan Ай бұрын
great explaination, loved it.
@Medusa0xf
@Medusa0xf 27 күн бұрын
Thank you!
@H4ckerNafeed
@H4ckerNafeed 24 күн бұрын
The tiny note name? where u using to save payloads?
@senlin9414
@senlin9414 26 күн бұрын
Great Content, but the background shouldn't be flickering.
@Medusa0xf
@Medusa0xf 15 күн бұрын
Thanks for the tip
@testauthoritytes9917
@testauthoritytes9917 Ай бұрын
Medusa reminds me modlishka. Anyway great explanation. Some more points - you have worked on lazy loading cache hit and cache miss architecture that has a condition that this type if cache poisioning is only real of cache is updated. There are some more architecture you may want to explore, its write through and session storing. For write through architecture , cache cant be poisoned or updated to be delivered to multiple users for same content if you are not writing to DB. For session storing cached architecture mechanisms xss will fall short and you may want to try csrf.
@Medusa0xf
@Medusa0xf 27 күн бұрын
How about you share some articles for this on my server?
@wmpdx7
@wmpdx7 23 күн бұрын
Love you 😘👌
@nishantdalvi9470
@nishantdalvi9470 Ай бұрын
Please make this sort of video for Oauth misconfiguration as well
@Medusa0xf
@Medusa0xf 27 күн бұрын
Noted
@smilehackermax
@smilehackermax Ай бұрын
Nice one!
@Medusa0xf
@Medusa0xf 27 күн бұрын
Thanks!
@mysteriousministar2481
@mysteriousministar2481 Ай бұрын
Nice video
@Medusa0xf
@Medusa0xf 27 күн бұрын
Thank you!
@halfman.halfamazing3113
@halfman.halfamazing3113 27 күн бұрын
Unable to focus while stuff running on the background with distracting music, it would be better if the video is some calm or lofi stuff.
@Aquax1000
@Aquax1000 Ай бұрын
Yo man hook me up with some BAC resources (not basics)
@Medusa0xf
@Medusa0xf 27 күн бұрын
You should hear this podcast. kzbin.info/www/bejne/rWWQkKqalLeYjpYsi=hnBOCR2AioksJdFH
@Aquax1000
@Aquax1000 27 күн бұрын
@@Medusa0xf I hate that smile do you have any other resources where you are the only one like same as this video. I love your blog but it's very nice to see any video on that. If you don't mind Medusa I'm doing fully manual testing now including BAC,Auth and OAuth so can you tell me am I missing out on something here ?
@Bluesurfer-w8g
@Bluesurfer-w8g Ай бұрын
Ps : don't use glitch screen background when explaining something, it's uncomfortable
@testauthoritytes9917
@testauthoritytes9917 Ай бұрын
How comfortable is that when you have your website hosting different image or probably your user poset is changed or someone rides csrf and transfer legit amount from your digital wallet to some of your friend that you don't know. Get used it if you are blue 🔵, life will be less stressful 😊
@pratiksawant8119
@pratiksawant8119 Ай бұрын
Agree
@shouvikkundu8289
@shouvikkundu8289 28 күн бұрын
Yup it's kinda make us distract
@Medusa0xf
@Medusa0xf 27 күн бұрын
Okay
@bambastala7446
@bambastala7446 17 күн бұрын
Don't use anime it's distracting
Exploiting path delimiters for web cache deception - Lab#02
19:46
Shein - Live bug bounty recon on Hackerone
44:25
gotr00t?
Рет қаралды 4,4 М.
What type of pedestrian are you?😄 #tiktok #elsarca
00:28
Elsa Arca
Рет қаралды 31 МЛН
風船をキャッチしろ!🎈 Balloon catch Challenges
00:57
はじめしゃちょー(hajime)
Рет қаралды 89 МЛН
كم بصير عمركم عام ٢٠٢٥😍 #shorts #hasanandnour
00:27
hasan and nour shorts
Рет қаралды 4,7 МЛН
The Internet Will End Soon…
17:54
Pursuit of Wonder
Рет қаралды 3 МЛН
The Most Legendary Programmers Of All Time
11:49
Aaron Jack
Рет қаралды 615 М.
When a CIA Hacker Goes Rogue
23:09
TyFrom99
Рет қаралды 2,4 МЛН
How not to get stuck when learning web security? Louis Nyffenegger from PentesterLab
55:16
Bug Bounty Reports Explained
Рет қаралды 4,9 М.
Practical Web Cache Poisoning: Redefining 'Unexploitable'
43:55
Solving a REAL investigation using OSINT
19:03
Gary Ruddell
Рет қаралды 187 М.
I used AI to hack this website...
23:23
Tech Raj
Рет қаралды 131 М.
What type of pedestrian are you?😄 #tiktok #elsarca
00:28
Elsa Arca
Рет қаралды 31 МЛН