Collected research
The Cookie Monster in Your Browsers
A tour of how browsers and servers disagree about cookies: a subdomain can force a cookie onto its parent (cookie tossing), oversized cookies make a server reject requests (cookie bomb), and servers that still split on commas accept injected cookies. The result is CSRF token fixation, an HttpOnly bypass, and stealing OAuth authorization codes via a bombed redirect.
Record
- Researcher
- filedescriptor
- Published by
- Speaker Deck
- Date
- Format
- Slides
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of filedescriptor, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .