
10/24/2019 · Rustam Lalkaka
What this post added
This post details Cloudflare's defenses against three Cache Poisoning Denial of Service (CPDoS) vulnerabilities. It explains how Cloudflare mitigates the HTTP Header Method Override (HMO) attack by including specific method override headers in cache keys, and how the Oversized HTTP Headers (HHO) and HTTP Meta Characters attacks are mitigated by Cloudflare's default behavior of not caching 400 error responses. Specific recommendations are provided for Microsoft IIS users with request filtering enabled.