Skip to main content

hunt-cache-poisoning

在授权渗透测试中挖掘 Web 缓存投毒与缓存欺骗(web cache poisoning / cache deception)。当目标前有缓存层(CDN/反代/Varnish)且缓存键未覆盖某些影响响应的输入(unkeyed header/参数/解析差异)时使用——典型场景:X-Forwarded-Host 反射进响应被缓存、unkeyed 参数、缓存键规范化差异、静态扩展名欺骗缓存私有页。适用目标类型 Web / CDN。触发场景包括用户说"测下缓存投毒""X-Forwarded-Host 能不能毒缓存""缓存欺骗看一下""unkeyed 输入有没有"。输出:投毒/欺骗可行性 + 被缓存证据的 finding(含 killed 记录)。

Jump to install

Source facts

Repository
galact-byte/galact-Skills
Last source activity
August 6, 2026 at 06:23
Detected SKILL.md language
Chinese
Stars
4
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.