Collected research
The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws
A fully automated black-box framework registers accounts, logs in (including via single sign-on) and then removes cookie subsets to work out which cookies authenticate and whether they are exposed over cleartext HTTP or to JavaScript. Auditing 25,000 domains it found over 10,000 leaking authentication cookies in the clear and 9,324 where a hijacker reaches personal data.
Record
- Researcher
- Kostas Drakonakis, Sotiris Ioannidis and Jason Polakis
- Published by
- cs.uic.edu
- Format
- Whitepaper
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Kostas Drakonakis, Sotiris Ioannidis and Jason Polakis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .