Web Hack List

Collected research

The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private Information

Sites that still serve some pages over HTTP leak their non-session cookies to any network eavesdropper. An audit of 25 major services shows those stolen cookies expose search history, home and work addresses, purchase history and contact lists, and can even send mail from the account; a month of campus traffic found 282,000 exposed accounts, and Tor users are deanonymisable the same way.

Record

Researcher
Suphannee Sivakorn, Iasonas Polakis and Angelos D. Keromytis
Published by
ieee-security.org
Format
Whitepaper
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Suphannee Sivakorn, Iasonas Polakis and Angelos D. Keromytis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .