Stealing HttpOnly cookies with the cookie sandwich technique
portswigger.net | research | #cookies | #exfiltration | #session-security | #httponly | #tomcat | #cookie-parsing
Summary
The cookie sandwich technique wraps a session cookie between quoted values and legacy $Version attributes, making Tomcat misparse the header and expose HttpOnly cookies to scripts.
- Published
- Collected
Skip to content