Collected research
Reusing Cookies
SaaS vendors that let customers point a subdomain at them by CNAME often share one session cookie across the vendor domain and every customer domain. An attacker signs up for a trial and retargets his own cookie Domain attribute at a customer subdomain, gaining his account there: phishing and fake login pages, open redirect, stored XSS, and other tenants private documents.
Record
- Researcher
- Ricardo Iramar dos Santos
- Published by
- Medium
- Date
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Ricardo Iramar dos Santos, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .