Web Hack List

Collected research

Racing to downgrade users to cookie-less authentication

Applications that fall back to URL-borne session tokens decide by setting a probe cookie and checking it comes back. Saturating Firefox's per-domain cookie jar from 20 iframed subdomains evicts that probe in about 100ms, winning the race so the app downgrades to cookie-less auth; the token then leaks through Referer to any persistent image. Working PHP/JavaScript included.

Record

Researcher
kuza55
Published by
kuza55.blogspot.com
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of kuza55, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .