Later archive addition
Are Your Cookies Telling Your Fortune?
The paper measures weak signing secrets in Node.js applications using cookie-session and public OSINT. It gathers candidate secrets, cracks signed cookies, and demonstrates how recovered keys can forge authenticated session state in Passport applications using both OpenID and local authentication.
Record
- Format
- Whitepaper
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.