1. Web Security Academy
  2. Web cache poisoning
  3. Exploiting cache design flaws
  4. Lab

Lab: Web cache poisoning with an unkeyed cookie


This lab is vulnerable to web cache poisoning because cookies aren't included in the cache key. A user visits the home page roughly once a minute. To solve this lab, poison the cache with a response that executes alert(1) in the visitor's browser.