Web Hack List

Top 10 winner

Cookie Crumbles: Breaking and Fixing Web Session Integrity

Cookie Crumbles: Breaking and Fixing Web Session Integrity (Paper)

Studies cookie integrity across browsers and server frameworks and shows that the Secure attribute, cookie prefixes, SameSite and synchronizer CSRF tokens can be composed or implemented in ways that still allow session fixation and cross-origin request forgery. Nine of the top thirteen frameworks were affected, producing twelve CVEs and changes to the cookie standard.

Record

Document
Cookie Crumbles: Breaking and Fixing Web Session Integrity (Paper)
Researcher
Marco Squarcina, Pedro Adão, Lorenzo Veronese and Matteo Maffei
Published by
USENIX Association
Date
Format
Whitepaper
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Marco Squarcina, Pedro Adão, Lorenzo Veronese and Matteo Maffei, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .