CDNio (Easy) WIP

Description

Race against time! Tweak CDN and caching magic to make web pages load at lightning speed. Minimize cache misses and watch your load times drop!

  • Difficult -> Easy

  • State -> Active

Summary

  • An application with a profile page that fetches information from the logged-in user

  • The app has a bot with admin privileges that caches indicated pages via the /visit route

  • Cache Deception attack on the /profile route via the Bot´s privileges

  • Accessing the profile of the admin user returns the flag in the API-Key field

Writeup

Last updated