Web Hack List

Collected research

Cookie forcing

Explains how an attacker can force cookie values into an HTTPS application despite Secure-cookie confidentiality. The post maps untrusted cookie contents to DOM or JSON-evaluation injection, double-submit CSRF failures and login/session problems, showing why applications need cookie integrity as well as transport protection.

Record

Researcher
Chris Evans
Published by
Scarybeast Security
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .