Web Hack List

Other nomination

The Cookie Monster in Your Browsers

A subdomain can force duplicate cookies onto its parent, while oversized cookies can make servers reject requests and legacy comma splitting can inject additional cookie values. The slides combine these browser/server discrepancies into CSRF token fixation, HttpOnly bypasses, and theft of OAuth authorization codes from blocked redirects.

Record

Researcher
filedescriptor
Published by
Speaker Deck
Date
Format
Slides

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of filedescriptor, first published at the original source. Preserved copies are kept so the citation survives its host.