Skip to main content

Web Cache Deception Attack Uncovers New Attack Vector

A new attack vector has been identified to exploit a new vulnerability affecting many web caching systems.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A new attack vector has been identified to exploit a new vulnerability affecting many web caching systems.

Threat details

The purpose of the web cache technology is to store commonly accessed web based resources. This benefits the end user as web forms are able to be retrieved faster by reducing the processing load and latency.

The attack method uses a web caching behaviour when a resource is requested that no longer exists, a default is returned with the same page address.

There is the possibility for sensitive data to be stored up to five hours by an actor manipulating the page returned link with .PHP and not .CSS extensions. This attack is not limited to .PHP in fact the following extensions can be returned to steal sensitive data including aif, aiff, au, avi, bin, bmp, cab, carb, cct, cdf, class, css, doc, dcr, dtd, gcf, gff, gif, grv, hdml, hqx, ico, ini, jpeg, jpg, js, mov, mp3, nc, pct, ppc, pws, swa, swf, txt, vbs, w32, wav, wbmp, wml, wmlc, wmls, wmlsc, xsd, zip

Depending on the nature of the site the actor could obtain sensitive details including identification details, financial details and personal details such as address, phone number and full names.


Remediation advice

To mitigate the risk of being exploited by the attack it is recommended that:

Remediation steps

Type Step
  • Configure the cache mechanism to cache files only if their HTTP caching headers allow will resolve the root issue allowing protection for visitors.
  • Configure catching by content type rather than extension where possible.
  • Extra vigilance should be exercised when following suspicious links even where links lead to trusted sites. Attention should be paid to the full URL looking for suspicious extensions.

Last edited: 17 February 2020 11:41 am