Cookie Chaos: How to bypass __Host and __Secure cookie prefixes
portswigger.net | research | #cookies | #asp-net | #unicode | #django | #cookie-tossing | #session-security
Summary
Unicode whitespace bypasses __Host- and __Secure- cookie prefixes: browsers treat the cookie as unrestricted, but servers such as Django and ASP.NET trim the character and honour the protected name.
- Published
- Collected
Skip to content