index.md (8974B)
1 --- 2 title: "Web Cache Deception" 3 topic: "Web Cache Deception" 4 topicSlug: "web-cache-deception" 5 sourcePath: "Web Cache Deception/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Web%20Cache%20Deception/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Web Cache Deception 12 13 > Web Cache Deception (WCD) is a security vulnerability that occurs when a web server or caching proxy misinterprets a client's request for a web resource and subsequently serves a different resource, which may often be more sensitive or private, after caching it. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [Caching Sensitive Data](#caching-sensitive-data) 20 * [Caching Custom JavaScript](#caching-custom-javascript) 21 * [CloudFlare Caching](#cloudflare-caching) 22 * [Labs](#labs) 23 * [References](#references) 24 25 ## Tools 26 27 * [PortSwigger/param-miner](https://github.com/PortSwigger/param-miner) - Web Cache Poisoning Burp Extension 28 29 ## Methodology 30 31 Example of Web Cache Deception: 32 33 Imagine an attacker lures a logged-in victim into accessing `http://www.example.com/home.php/non-existent.css` 34 35 1. The victim's browser requests the resource `http://www.example.com/home.php/non-existent.css` 36 2. The requested resource is searched for in the cache server, but it's not found (resource not in cache). 37 3. The request is then forwarded to the main server. 38 4. The main server returns the content of `http://www.example.com/home.php`, most probably with HTTP caching headers that instruct not to cache this page. 39 5. The response passes through the cache server. 40 6. The cache server identifies that the file has a CSS extension. 41 7. Under the cache directory, the cache server creates a directory named home.php and caches the imposter "CSS" file (non-existent.css) inside it. 42 8. When the attacker requests `http://www.example.com/home.php/non-existent.css`, the request is sent to the cache server, and the cache server returns the cached file with the victim's sensitive `home.php` data. 43 44  45 46 ### Caching Sensitive Data 47 48 **Example 1** - Web Cache Deception on PayPal Home Page 49 50 1. Normal browsing, visit home : `https://www.example.com/myaccount/home/` 51 2. Open the malicious link : `https://www.example.com/myaccount/home/malicious.css` 52 3. The page is displayed as /home and the cache is saving the page 53 4. Open a private tab with the previous URL : `https://www.example.com/myaccount/home/malicious.css` 54 5. The content of the cache is displayed 55 56 Video of the attack by Omer Gil - Web Cache Deception Attack in PayPal Home Page 57 [](https://vimeo.com/249130093) 58 59 **Example 2** - Web Cache Deception on OpenAI 60 61 1. Attacker crafts a dedicated .css path of the `/api/auth/session` endpoint. 62 2. Attacker distributes the link 63 3. Victims visit the legitimate link. 64 4. Response is cached. 65 5. Attacker harvests JWT Credentials. 66 67 ### Caching Custom JavaScript 68 69 1. Find an un-keyed input for a Cache Poisoning 70 71 ```js 72 Values: User-Agent 73 Values: Cookie 74 Header: X-Forwarded-Host 75 Header: X-Host 76 Header: X-Forwarded-Server 77 Header: X-Forwarded-Scheme (header; also in combination with X-Forwarded-Host) 78 Header: X-Original-URL (Symfony) 79 Header: X-Rewrite-URL (Symfony) 80 ``` 81 82 2. Cache poisoning attack - Example for `X-Forwarded-Host` un-keyed input (remember to use a buster to only cache this webpage instead of the main page of the website) 83 84 ```js 85 GET /test?buster=123 HTTP/1.1 86 Host: target.com 87 X-Forwarded-Host: test"><script>alert(1)</script> 88 89 HTTP/1.1 200 OK 90 Cache-Control: public, no-cache 91 [..] 92 <meta property="og:image" content="https://test"><script>alert(1)</script>"> 93 ``` 94 95 ## Tricks 96 97 The following URL format are a good starting point to check for "cache" feature. 98 99 * `https://example.com/app/conversation/.js?test` 100 * `https://example.com/app/conversation/;.js` 101 * `https://example.com/home.php/non-existent.css` 102 103 ## Detecting Web Cache Deception 104 105 1. Detecting delimiter discrepancies: `/path/<dynamic-resource>;<static-resource>` 106 * For example: `/settings/profile;script.js` 107 * If the origin server uses `;` as a delimiter but the cache isn't 108 * The cache interprets the path as: `/settings/profile;script.js` 109 * The origin server interprets the path as: `/settings/profile` 110 * For more delimiter characters: see [Web cache deception lab delimiter list](https://portswigger.net/web-security/web-cache-deception/wcd-lab-delimiter-list) 111 2. Detecting normalization: `/wcd/..%2fprofile` 112 * If the origin server resolved the path traversal sequence but the cache isn't 113 * The cache interprets the path as: `/wcd/..%2fprofile` 114 * The origin server interprets the path as: `/profile` 115 116 ## CloudFlare Caching 117 118 CloudFlare caches the resource when the `Cache-Control` header is set to `public` and `max-age` is greater than 0. 119 120 * The Cloudflare CDN does not cache HTML by default 121 * Cloudflare only caches based on file extension and not by MIME type: [cloudflare/default-cache-behavior](https://developers.cloudflare.com/cache/about/default-cache-behavior/) 122 123 In Cloudflare CDN, one can implement a `Cache Deception Armor`, it is not enabled by default. 124 When the `Cache Deception Armor` is enabled, the rule will verify a URL's extension matches the returned `Content-Type`. 125 126 CloudFlare has a list of default extensions that gets cached behind their Load Balancers. 127 128 | | | | | | | | 129 |-------|------|------|------|------|-------|------| 130 | 7Z | CSV | GIF | MIDI | PNG | TIF | ZIP | 131 | AVI | DOC | GZ | MKV | PPT | TIFF | ZST | 132 | AVIF | DOCX | ICO | MP3 | PPTX | TTF | CSS | 133 | APK | DMG | ISO | MP4 | PS | WEBM | FLAC | 134 | BIN | EJS | JAR | OGG | RAR | WEBP | MID | 135 | BMP | EOT | JPG | OTF | SVG | WOFF | PLS | 136 | BZ2 | EPS | JPEG | PDF | SVGZ | WOFF2 | TAR | 137 | CLASS | EXE | JS | PICT | SWF | XLS | XLSX | 138 139 Exceptions and bypasses: 140 141 * If the returned Content-Type is application/octet-stream, the extension does not matter because that is typically a signal to instruct the browser to save the asset instead of to display it. 142 * Cloudflare allows .jpg to be served as image/webp or .gif as video/webm and other cases that we think are unlikely to be attacks. 143 * [Bypassing Cache Deception Armor using .avif extension file - fixed](https://hackerone.com/reports/1391635) 144 145 ## Labs 146 147 * [PortSwigger Labs for Web Cache Deception](https://portswigger.net/web-security/all-labs#web-cache-poisoning) 148 149 ## References 150 151 * [Cache Deception Armor - Cloudflare - May 20, 2023](https://web.archive.org/web/20230520042703/https://developers.cloudflare.com/cache/cache-security/cache-deception-armor/) 152 * [Exploiting cache design flaws - PortSwigger - May 4, 2020](https://web.archive.org/web/20260117063619/https://portswigger.net/web-security/web-cache-poisoning/exploiting-design-flaws) 153 * [Exploiting cache implementation flaws - PortSwigger - May 4, 2020](https://web.archive.org/web/20200919065854/https://portswigger.net/web-security/web-cache-poisoning/exploiting-implementation-flaws) 154 * [How I Test For Web Cache Vulnerabilities + Tips And Tricks - bombon (0xbxmbn) - July 21, 2022](https://web.archive.org/web/20251213233158/https://bxmbn.medium.com/how-i-test-for-web-cache-vulnerabilities-tips-and-tricks-9b138da08ff9) 155 * [OpenAI Account Takeover - Nagli (@naglinagli) - March 24, 2023](https://web.archive.org/web/20230412113849/https://twitter.com/naglinagli/status/1639343866313601024) 156 * [Practical Web Cache Poisoning - James Kettle (@albinowax) - August 9, 2018](https://web.archive.org/web/20180810041437/https://portswigger.net/blog/practical-web-cache-poisoning) 157 * [Shockwave Identifies Web Cache Deception and Account Takeover Vulnerability affecting OpenAI's ChatGPT - Nagli (@naglinagli) - July 15, 2024](https://web.archive.org/web/20251010025345/https://www.shockwave.cloud/blog/shockwave-works-with-openai-to-fix-critical-chatgpt-vulnerability) 158 * [Web Cache Deception Attack - Omer Gil - February 27, 2017](https://web.archive.org/web/20170308135717/https://omergil.blogspot.fr:80/2017/02/web-cache-deception-attack.html) 159 * [Web Cache Deception Attack leads to user info disclosure - Kunal Pandey (@kunal94) - February 25, 2019](https://web.archive.org/web/20191217174659/https://medium.com/@kunal94/web-cache-deception-attack-leads-to-user-info-disclosure-805318f7bb29) 160 * [Web Cache Entanglement: Novel Pathways to Poisoning - James Kettle (@albinowax) - August 5, 2020](https://web.archive.org/web/20200805185253/https://portswigger.net/research/web-cache-entanglement) 161 * [Web cache poisoning - PortSwigger - May 4, 2020](https://web.archive.org/web/20200416160055/https://portswigger.net/web-security/web-cache-poisoning)