
CYBERSECURITY
FEATURED ANALYSIS
Stealing HttpOnly cookies with the cookie sandwich technique
SOURCE
PortSwigger Research
DATE
READ
1 min read
In this post, I will introduce the “cookie sandwich” technique which lets you bypass the HttpOnly flag on certain servers. This research follows on from Bypassing WAFs with the phantom $Version cookie
In this post, I will introduce the “cookie sandwich” technique which lets you bypass the HttpOnly flag on certain servers. This research follows on from Bypassing WAFs with the phantom $Version cookie