Skip to content

Cache Sentry 0.3.2

Latest

Choose a tag to compare

@CodeWithSamzy CodeWithSamzy released this 28 Sep 13:46

Passive Chrome extension that flags web cache deception signals while you browse.

Install

  1. Download cache-sentry-0.3.2-unpacked.zip below and unzip it. You get a single folder named cache-sentry.
  2. Keep that folder somewhere permanent -- Chrome reads it every time it starts, and the extension stops working if the folder is moved or deleted.
  3. Open chrome://extensions, turn on Developer mode (top right), click Load unpacked, and select the cache-sentry folder.
  4. Pin Cache Sentry from the puzzle-piece menu so the badge count is visible.

Chrome will warn that the extension is not from the store. That warning is expected for any extension installed this way. Prefer the source? Download the repository zip and point Load unpacked at the repository folder instead.

What it flags

A request is reported only when all of these hold: it carried a real session cookie (analytics cookies do not count), its URL looks like a static asset or carries a delimiter (%2e%2e, %2f%2f, %00, %23, %3f, or a ; path parameter), the response came back as a document or data payload instead of the asset type the URL promises, the response is shareable-cacheable, and its Vary header does not name a credential.

The popup shows each finding, what the response contradicted, which cache headers were present, a readout of what the cache did with this tab's page loads, and a log of the requests that looked suspicious and were rejected with the reason.

This is a signal, not proof. Verify manually with curl or Burp before treating anything as a real vulnerability.

Notes

  • Nothing leaves the browser. Findings live in chrome.storage.session and are cleared when the browser closes.
  • Fully passive: it never sends a request of its own. There is deliberately no "test the variants" button, because firing delimiter tricks can cache your own authenticated page in a shared cache.
  • Built and tested on this commit: 90 unit tests plus 7 browser scenarios against a real Chrome.
  • Author: CodeWithSamzy. MIT licensed.