Cookie Attacks

About I just wandered the Internet and encountered cookie tossing by a tweet from S1r1us Here is just a collection of writeups related to this technique, along with other researches related to cookie security. Researches Cookie tossing video by Reconless: Very quick introduction on how this attack works. Research covered by this video: Cookie Tossing to RCE on Google Cloud Jupyter lab. The cookie monster in our browsers: Very detailed research by filedescriptor on cookie security and attacks.
[Read more]

Relative Path Overwrite research

About This is from a video by Reconless: https://www.youtube.com/watch?v=0-sA_kAVw74. The links below will be for my reference if I decided to revisit this concept later. I hope this attack vector is not dead now, but cool to know this existed regardless. Researches RPO whitepaper RPO Gadgets
[Read more]