Collected research
Cookie forcing
Explains how an attacker can force cookie values into an HTTPS application despite Secure-cookie confidentiality. The post maps untrusted cookie contents to DOM or JSON-evaluation injection, double-submit CSRF failures and login/session problems, showing why applications need cookie integrity as well as transport protection.
Record
- Researcher
- Chris Evans
- Published by
- Scarybeast Security
- Topic
- Identity
In the archive
Related sources
- Login CSRF and Cookie-Integrity research Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Chris Evans, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .