Web Hack List

Collected research

Cookiejacking

Valotta chains an IE zero-day that loads a local cookie file into an iframe with Paul Stone's drag-and-drop content extraction, stealing any cookie including HttpOnly and Secure ones without XSS. An SMB UNC image request leaks the Windows username over NTLM, the user agent gives the OS, and an onfocus scrollspeed trick collapses text selection into a single click.

Record

Researcher
Rosario Valotta
Published by
archive.conference.hitb.org
Format
Whitepaper
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Rosario Valotta, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .