Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Stealing HttpOnly cookies with the cookie sandwich technique

Summary

The cookie sandwich technique wraps a session cookie between quoted values and legacy $Version attributes, making Tomcat misparse the header and expose HttpOnly cookies to scripts.
Published
Collected

original ↗

Related coverage

back