Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Vulnerability Development mailing list archives

Re: Cookies
From: George <georger () NLS NET>
Date: Sun, 6 Aug 2000 17:19:47 -0400

Yep, I thought about it some.  Never did an experiments however.
I assume that it is illegal to break into someone else's Web server
in this way.

I would assume that if their webserver is requesting information stored on
my computer, it is their responsibility to verify that data, not mine?

 The nickname I gave to the problem is "poison cookie".

Excellent name. One of the possibilities I'm currently looking at is if
someone were to write a program that goes thru their cookies and sets all
digits it finds to zero, could this cause a divide by zero type error back
at the server end. The other possibility we discussed was embedding odd
characters (ascii values or unicode) into the existing cookies and what
possible problems that might cause for a cookie parser.

I guess there is a third possibility as well, if a cookie is say 200 bytes
long, lenghtening it to 20,000 bytes could possibly cause a problem.

Geo.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]