Web Hack List

Collected research

Reusing Cookies

SaaS vendors that let customers point a subdomain at them by CNAME often share one session cookie across the vendor domain and every customer domain. An attacker signs up for a trial and retargets his own cookie Domain attribute at a customer subdomain, gaining his account there: phishing and fake login pages, open redirect, stored XSS, and other tenants private documents.

Record

Researcher
Ricardo Iramar dos Santos
Published by
Medium
Date
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Ricardo Iramar dos Santos, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .