当前位置:首页 > 报告详情

马丁·多伊纳德_全部缓存弯曲Web缓存利用规则_WP.pdf

上传人: 张** 编号:175444 2024-09-13 18页 726.13KB

1、Gotta Cache em allbending the rules of web cache exploitationMartin Doyhenard-tincho_508Through the years,we have seen many attacks exploiting web caches to hijack sensitiveinformation or store malicious payloads.However,as CDNs became more popular,new discrepancies between proprietary URL parserspr

2、ove that we have only seen the tip of the iceberg.In this paper will explore how different HTTP servers and proxies behave when parsing speciallycrafted URLs and explore ambiguities in the RFC that lead to path confusion.It will also introduce aset of novel techniques that can be used to leverage pa

3、rser discrepancies and achieve arbitraryweb cache poisoning and deception in countless websites and CDN providers.OutlineBackgroundWeb cachesPoisoning and deceptionURL discrepanciesDelimitersNormalizationArbitrary Web Cache DeceptionLimitationsStatic extensionsStatic directoriesStatic filesArbitrary

4、 Web Cache PoisoningKey normalizationExploiting back-end delimitersExploiting front-end delimitersCache-What-WhereDefenceBackgroundWeb cachesWeb caches have been around since the beginning of the internet.This technology works byfingerprinting requests using a key,which in most cases will be built u

5、sing some or all parts of therequested URL,and mapping the key with stored static responses.In recent years,most productive systems incorporate caching by setting Content Delivery Networks(CDNs)with providers like CloudFlare,Akamai,or CloudFront.CDNs can be seen as a network ofweb cache proxies that

6、 are distributed around the globe.They serve static responses,increasingthe efficiency and scalability of a system.This paper focuses on URL parsing discrepancies that exist between different application serversand CDN proxies,but the same techniques can be applied to any type of web cache,including

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要探讨了如何利用不同HTTP服务器和代理在解析特殊构造URL时存在的差异,以及RFC中的模糊性导致的路径混淆,来实施任意Web缓存欺骗和污染。文章首先介绍了Web缓存的工作原理,然后详细分析了URL解析中的分隔符、URL标准化等差异,并提出了利用这些差异的新技术。文章还介绍了如何通过静态扩展、静态目录、静态文件等规则来欺骗缓存,以及如何通过键标准化、后端分隔符、前端分隔符等方法来污染缓存。最后,文章讨论了如何将Web缓存欺骗和污染技术结合起来,实现更严重的攻击。文章还提供了防御这些攻击的建议。
如何利用URL解析差异进行网络缓存欺骗? 如何防御网络缓存欺骗攻击? 网络缓存欺骗攻击有哪些实际应用场景?
客服
商务合作
小程序
服务号
折叠