Web Hack List

Other nomination

Racing to downgrade users to cookie-less authentication

Applications that fall back to URL-borne session tokens decide by setting a probe cookie and checking it comes back. Saturating Firefox's per-domain cookie jar from 20 iframed subdomains evicts that probe in about 100ms, winning the race so the app downgrades to cookie-less auth; the token then leaks through Referer to any persistent image. Working PHP/JavaScript included.

Record

Researcher
kuza55

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of kuza55, first published at the original source. Preserved copies are kept so the citation survives its host.