Collected research
Cross-Site Cooking
Michal Zalewski's Full Disclosure advisory names three cookie-domain flaws: browsers accept cookies scoped to two-part ccTLDs such as *.com.pl; empty and trailing periods pass the domain check, so ".com." works against www.victim.com.; and an A record pointing evil.example.com at a victim's IP makes the browser relay attacker cookies to that server.
Record
- Researcher
- Michal Zalewski
- Published by
- lcamtuf.coredump.cx
- Format
- Code
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Michal Zalewski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .