1. Web Security Academy
  2. Web cache poisoning
  3. Exploiting
  4. Lab

Lab: Web cache poisoning with an unkeyed header

PRACTITIONER

This lab is vulnerable to web cache poisoning because it handles input from an unkeyed header in an unsafe way. A user visits the homepage roughly once every minute. To solve this lab, poison the cache with a response that executes alert(document.cookie) in the visitor's browser.

Tip: This lab supports the X-Forwarded-Host header.

Try Burp Suite for Free

Find web cache poisoning vulnerabilities using Burp Suite

Try for free