3 ms·
also, add httponly to your cookies then javascript cant see them
by k0nad 16y ago
also, add httponly to your cookies then javascript cant see them
- mhitza 16y agoIf the server supports the HTTP TRACE verb you can still get the cookie. It would be rare, but possible non the less.
- tptacek 16y agoThis is an almost cosmetic defense, because Javascript can still launch requests that will bear those cookies, even if it can't bank them for later. HttpOnly isn't evil, but it's not a solution to the problem.
- peripitea 16y agoSecurity noob follow-up: How do you exploit the fact that your javascript can launch requests bearing those cookies? I'm assuming your end goal is to get access to those cookies. Do you do something like POST the contents of the original HTTP request headers that follow your injected \r\n (including said cookies) to a malicious server?
- jaysoo 16y agoThe goal could be CSRF instead of actually reading the cookies. If there's a SessionID cookie for example, you can use JS to GET/POST the request to the server without needing to know the value of SessioID because the browser will send it as part of the request anyway. The HTTP Response Splitting vulnerability can have many implications, XSS and CSRF attacks are just some examples.
- peripitea 16y agoAh, right. Thanks!