Cached and Confused: Web Cache Deception in the Wild

12/21/2019
by   Seyed Ali Mirheidari, et al.
0

Web cache deception (WCD) is an attack proposed in 2017, where an attacker tricks a caching proxy into erroneously storing private information transmitted over the Internet and subsequently gains unauthorized access to that cached data. Due to the widespread use of web caches and, in particular, the use of massive networks of caching proxies deployed by content distribution network (CDN) providers as a critical component of the Internet, WCD puts a substantial population of Internet users at risk. We present the first large-scale study that quantifies the prevalence of WCD in 340 high-profile sites among the Alexa Top 5K. Our analysis reveals WCD vulnerabilities that leak private user data as well as secret authentication and authorization tokens that can be leveraged by an attacker to mount damaging web application attacks. Furthermore, we explore WCD in a scientific framework as an instance of the path confusion class of attacks, and demonstrate that variations on the path confusion technique used make it possible to exploit sites that are otherwise not impacted by the original attack. Our findings show that many popular sites remain vulnerable two years after the public disclosure of WCD. Our empirical experiments with popular CDN providers underline the fact that web caches are not plug play technologies. In order to mitigate WCD, site operators must adopt a holistic view of their web infrastructure and carefully configure cache settings appropriate for their applications.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/13/2021

The Master and Parasite Attack

We explore a new type of malicious script attacks: the persistent parasi...
research
04/09/2020

The Web is Still Small After More Than a Decade

Understanding web co-location is essential for various reasons. For inst...
research
05/18/2022

Analysing and strengthening OpenWPM's reliability

Automated browsers are widely used to study the web at scale. Their prem...
research
11/17/2019

Web-sites password management (in)security: Evidence and remedies

Single-factor password-based authentication is generally the norm to acc...
research
11/02/2018

Large-Scale Analysis of Style Injection by Relative Path Overwrite

Relative Path Overwrite (RPO) is a recent technique to inject style dire...
research
05/14/2018

User Blocking Considered Harmful? An Attacker-controllable Side Channel to Identify Social Accounts

This paper presents a practical side-channel attack that identifies the ...
research
11/11/2021

Classification of URL bitstreams using Bag of Bytes

Protecting users from accessing malicious web sites is one of the import...

Please sign up or login with your details

Forgot password? Click here to reset