← Back to feed
research PortSwigger Research

Stealing HttpOnly cookies with the cookie sandwich technique

PortSwigger Research •

In this post, I will introduce the "cookie sandwich" technique which lets you bypass the HttpOnly flag on certain servers.

Read the full story PortSwigger Research →

Related Coverage

research MacSync under the microscope: new delivery methods and a new payload Kaspersky Securelist · Sep 24 research Russia Escalating Hybrid Attacks Across Europe Recorded Future · Sep 24 research HTTP/3 in Burp Suite - it’s time to find a bigger wordlist PortSwigger Research · Sep 23