3 ms·
Maybe I'm missing something, but is the exploit somehow generating a cache miss? Otherwise everything that's already in cache isn't vulnerable to this right? No
by Elte 7y ago
Maybe I'm missing something, but is the exploit somehow generating a cache miss? Otherwise everything that's already in cache isn't vulnerable to this right? Not that it makes it in any way less scary, but slightly more complicated at least..
- paulhodge 7y agoYeah, that’s part of it. The attacker wants to hit a url that isn’t already cached by CDN. That might be easy or hard depending on the site. Like if the CDN just has a 30 minute TTL, the attacker will need to be the first request right after the 30 minutes expires.