Cache poison / deception
Unkeyed header and path-deception probes. Confirm with a second client. Harmless markers only.
Tags: cache, cdn, xss
Controlled probes
X-Forwarded-Host: attacker.exampleX-Forwarded-Scheme: nothttpsX-Original-URL: /account/account/settings/x.css/account/settings%2f..%2f..%2fstatic/app.jsGET /path?unused=1 HTTP/1.1 (unkeyed query)
Source: https://portswigger.net/research/practical-web-cache-poisoning