SMRTR ProgrammingJan 23, 2025lobste.rs

Stealing HttpOnly cookies with the cookie sandwich technique

SMRTR summary

The "cookie sandwich" technique exploits server parsing of legacy cookies, using quotes and $Version to bypass HttpOnly flags, potentially exposing sensitive cookies to client-side scripts in Apache Tomcat and some Python frameworks.

SMRTR provides this summary for quick context. The original article belongs to lobste.rs.

Read the original article
SMRTR Programming

Get the next batch of curated stories in your inbox.

This archive is built from SMRTR newsletter stories. Subscribe for hand-picked stories without the extra noise.

Related Stories

Browse Programming
ProgrammingAug 23, 2026

Rust Glancer

Rust-analyzer's memory bloat stems from treating all 6,666 dependencies equally — a tiered, IntelliJ-style backend could fix that.