Web Cache Deception Attack Uncovers New Attack Vector
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The purpose of the web cache technology is to store commonly accessed web based resources. This benefits the end user as web forms are able to be retrieved faster by reducing the processing load and latency.
The attack method uses a web caching behaviour when a resource is requested that no longer exists, a default is returned with the same page address.
There is the possibility for sensitive data to be stored up to five hours by an actor manipulating the page returned link with .PHP and not .CSS extensions. This attack is not limited to .PHP in fact the following extensions can be returned to steal sensitive data including aif, aiff, au, avi, bin, bmp, cab, carb, cct, cdf, class, css, doc, dcr, dtd, gcf, gff, gif, grv, hdml, hqx, ico, ini, jpeg, jpg, js, mov, mp3, nc, pct, ppc, pws, swa, swf, txt, vbs, w32, wav, wbmp, wml, wmlc, wmls, wmlsc, xsd, zip
Depending on the nature of the site the actor could obtain sensitive details including identification details, financial details and personal details such as address, phone number and full names.
Remediation advice
To mitigate the risk of being exploited by the attack it is recommended that:Remediation steps
Last edited: 17 February 2020 11:41 am