Web Hack List

Top 10 winner

XSS: Gaining access to HttpOnly Cookie in 2012

Revisits HttpOnly after XST died, testing Silverlight, Flash and Java for a way to read Set-Cookie. Java is the winner: an applet calling URLConnection.getHeaderField reads the HttpOnly Set-Cookie header and hands it back to JavaScript, also as a one-liner via java.net.URL. Chaining a logout page first makes the cookie reissue during the XSS.

Record

Researcher
Aung Khant
Published by
seckb.yehg.net
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Aung Khant, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .