| Whitepaper: Cross-subdomain Cookie Attacks | |
|
I did a talk at Toorcon last weekend on exploiting client-side applications' trust in subdomains. Primarily, it formalized and demonstrated a few attacks on cookies, which implement security policies backwards by placing more trust in a subdomain of a trusted domain, rather than less, as the hierachical nature of DNS would suggest. --Mike Bailey
Set as favorite
Bookmark
Email This
Hits: 983 Comments (0)
![]() |






