Hacker News new | ask | show | jobs
by bkallus 315 days ago
Cache poisoning is also possible.

See https://youtu.be/aKPAX00ft5s?feature=shared&t=8730 for a relevant demo.

You can also (in principle) steal responses intended for other clients, and control responses that get delivered to other clients.