Web Hack List

Collected research

The Cookie Monster in Your Browsers

A tour of how browsers and servers disagree about cookies: a subdomain can force a cookie onto its parent (cookie tossing), oversized cookies make a server reject requests (cookie bomb), and servers that still split on commas accept injected cookies. The result is CSRF token fixation, an HttpOnly bypass, and stealing OAuth authorization codes via a bombed redirect.

Record

Researcher
filedescriptor
Published by
Speaker Deck
Date
Format
Slides
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of filedescriptor, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .