Collected research
UI Redressing Mayhem: HTTPOnly Bypass PayPwn Style
UI Redressing Mayhem: HttpOnly bypass PayPwn style
CVE-2012-0053 makes Apache echo request headers into a 400 error page, so an overlong cookie forces HttpOnly session cookies into readable HTML. On PayPal a history.paypal.com endpoint set an attacker-controlled monster cookie for .paypal.com in a single request, and framing the affected b.stats.paypal.com lifted the session cookies cross-domain.
Record
- Document
- UI Redressing Mayhem: HttpOnly bypass PayPwn style
- Researcher
- Luca De Fulgentis
- Published by
- blog.nibblesec.org
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Luca De Fulgentis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .