Collected research
Stealing HttpOnly cookies with the cookie sandwich technique
Introduces the cookie sandwich technique for exposing HttpOnly cookie values through discrepancies in how servers parse legacy quoted cookies. An attacker-controlled cookie can surround a protected cookie so an application reflects the combined value back into script-readable content.
Record
- Researcher
- Zakhar Fedotkin
- Published by
- PortSwigger Research
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Zakhar Fedotkin, first published at the original source. Preserved copies are kept so the citation survives its host.