Hacking Cookies in Modern Web Applications and Browsers
Hack In The Box Security Conference via YouTube
Overview
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore cookie-related vulnerabilities in modern web applications and browsers in this 45-minute conference talk from HITB GSEC 2015. Delve into topics such as insecure processing of secure flags, bypassing HttpOnly flags, cookie tampering, and underestimated XSS via cookies. Learn about the importance of secure cookie processing from both web application and browser perspectives, including discussions on HTTP Strict Transport Security (HSTS), the significance of session regeneration, and server-side invalidation. Gain insights from security expert Dawid Czagan, who has discovered vulnerabilities in major tech companies and shares his experience in bug hunting and web application security.
Syllabus
Intro
Motivation
Agenda
Secure flag & HSTS
Importance of regeneration
Server-side invalidation
HttpOnly flag
Domain attribute
Cookie tampering
Underestimated XSS via cookie
Conclusions
Taught by
Hack In The Box Security Conference