Top 10 winner
XSS: Gaining access to HttpOnly Cookie in 2012
Revisits HttpOnly after XST died, testing Silverlight, Flash and Java for a way to read Set-Cookie. Java is the winner: an applet calling URLConnection.getHeaderField reads the HttpOnly Set-Cookie header and hands it back to JavaScript, also as a one-liner via java.net.URL. Chaining a logout page first makes the cookie reissue during the XSS.
Record
- Researcher
- Aung Khant
- Published by
- seckb.yehg.net
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Aung Khant, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .