Collected research
Cookiejacking
Valotta chains an IE zero-day that loads a local cookie file into an iframe with Paul Stone's drag-and-drop content extraction, stealing any cookie including HttpOnly and Secure ones without XSS. An SMB UNC image request leaks the Windows username over NTLM, the user agent gives the OS, and an onfocus scrollspeed trick collapses text selection into a single click.
Record
- Researcher
- Rosario Valotta
- Published by
- archive.conference.hitb.org
- Format
- Whitepaper
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Rosario Valotta, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .