Web Hack List

Top 10 winner

Cookie Crumbles: Breaking and Fixing Web Session Integrity

Studies cookie integrity across browsers and server frameworks and shows that the Secure attribute, cookie prefixes, SameSite and synchronizer CSRF tokens can be composed or implemented in ways that still allow session fixation and cross-origin request forgery. Nine of the top thirteen frameworks were affected, producing twelve CVEs and changes to the cookie standard.

Record

Researcher
Marco Squarcina, Pedro Adão, Lorenzo Veronese and Matteo Maffei
Published by
USENIX Association
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Marco Squarcina, Pedro Adão, Lorenzo Veronese and Matteo Maffei, first published at the original source. Preserved copies are kept so the citation survives its host.