The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private Information
@article{Sivakorn2016TheCC, title={The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private Information}, author={Suphannee Sivakorn and Iasonas Polakis and A. Keromytis}, journal={2016 IEEE Symposium on Security and Privacy (SP)}, year={2016}, pages={724-742} }
The widespread demand for online privacy, also fueled by widely-publicized demonstrations of session hijacking attacks against popular websites, has spearheaded the increasing deployment of HTTPS. However, many websites still avoid ubiquitous encryption due to performance or compatibility issues. The prevailing approach in these cases is to force critical functionality and sensitive data access over encrypted connections, while allowing more innocuous functionality to be accessed over HTTP. In… CONTINUE READING
Supplemental Video
Figures, Tables, and Topics from this paper
51 Citations
That's the Way the Cookie Crumbles: Evaluating HTTPS Enforcing Mechanisms
- Computer Science
- WPES@CCS
- 2016
- 14
- PDF
(In-)Security of Cookies in HTTPS: Cookie Theft by Removing Cookie Flags
- Computer Science
- IEEE Transactions on Information Forensics and Security
- 2020
- 2
Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web Ecosystem
- Computer Science
- 2019 IEEE Symposium on Security and Privacy (SP)
- 2019
- 14
- PDF
Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion Attacks
- Computer Science
- CCS
- 2020
- PDF
The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws
- Computer Science
- CCS
- 2020
- 1
- Highly Influenced
O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web
- Computer Science
- USENIX Security Symposium
- 2018
- 13
- PDF
Sub-session hijacking on the web: Root causes and prevention
- Computer Science
- J. Comput. Secur.
- 2019
- 4
- Highly Influenced
- PDF
References
SHOWING 1-10 OF 88 REFERENCES
Triple Handshakes and Cookie Cutters: Breaking and Fixing Authentication over TLS
- Computer Science
- 2014 IEEE Symposium on Security and Privacy
- 2014
- 170
- PDF
Private Information Disclosure from Web Searches
- Computer Science
- Privacy Enhancing Technologies
- 2010
- 39
- PDF
Pretty-Bad-Proxy: An Overlooked Adversary in Browsers' HTTPS Deployments
- Computer Science
- 2009 30th IEEE Symposium on Security and Privacy
- 2009
- 22
- PDF
Upgrading HTTPS in mid-air: An empirical study of strict transport security and key pinning
- Computer Science
- NDSS
- 2015
- 84
- Highly Influential
- PDF
Cookies That Give You Away: The Surveillance Implications of Web Tracking
- Computer Science
- WWW
- 2015
- 148
- PDF