Light

Episode #891 Quiz

Poisoning Akamai
Date: 2022-10-04 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Akamai’s CDN used hop-by-hop header handling to desynchronize proxy parsing: a crafted GET with Connection: Content-Length caused the first proxy to split one request into two, cache attacker-chosen responses regionally, and serve poisoned content to other users. Akamai fixed parsing; customers mitigated via WAF rewrite rules.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the key storage flaw in Microsoft Teams that Vectra identified?
Question 2: What did Microsoft say about the Teams credential issue when Vectra reported it?
Question 3: In the Exchange zero-day discussion, what did GTSC say the exploit did after initial compromise?
Question 4: What was one of the workarounds Microsoft and GTSC discussed for the Exchange zero-day mitigation, and what problem did GTSC note about it?
Question 5: How did Akamai initially respond when Jacopo Tediosi reported the CDN smuggling flaw?
Cancel