🦞🌯 Lobster Roll

Thread

Yummy cookies across domains (github.com)

Stories related to "Yummy cookies across domains" across the full archive.

Yummy cookies across domains (github.com)
Yummy cookies across domains (2019) (github.blog)
Supporting Same-Site Cookies in Firefox 60 (blog.mozilla.org)
Stealing Chrome cookies without a password (mango.pdf.zone)
xombrero (opensource.conformal.com)
Google Native Client - Attack Surface and Vulnerabilities (blog.leafsr.com)
Wouldn't it be nice if we could cache across domains? (alexchamberlain.co.uk)
CRIME (imperialviolet.org)
Critical Java bug: Complete sandbox bypass via all major browsers on a fully patched Win7 (seclists.org)
Bugtraq: [SE-2012-01] Critical security issue affecting Java SE 5/6/7
Browsers should have been cars. Instead they’re shopping carts. (blogs.law.harvard.edu)
Pinkie Pie claims another $60k prize in Pwnium contest with full user-privilege exploit of Chrome (googlechromereleases.blogspot.com)
A Tale of Two Firefox Bugs (youtube.com)
SSL certificate validation and DNSSEC (jpmens.net)
The First Few Milliseconds of an HTTPS Connection (2009) (moserware.com)
Mailvelope - client-side PGP encryption for webmail (mailvelope.com)
Google Accidentally Transmits Self-Destruct Code to Army of Chrome Browsers (wired.com)
UI Redressing Mayhem: HttpOnly bypass PayPwn style (blog.nibblesec.org)
An Introduction to Mozilla Persona (davidwalsh.name)
CRIME: A vulnerability in the SPDY protocol (imperialviolet.org)
This vulnerability no longer exists, but it's a good description of a non-obvious bug.
Pwn2Own and Pwnium 3 (blog.chromium.org)
How we hacked Facebook with OAuth2 and Chrome bugs (homakov.blogspot.com)
Any Firefox add-on people out there? [Plugin for validating SSL via DNS] (blather.michaelwlucas.com)
Protecting Mozilla Firefox users on the web (garykwong.wordpress.com)
What Blink means for Chrome Security (plus.google.com)
libcurl - tailmatching them cookies (daniel.haxx.se)
MWR Labs Pwn2Own 2013 Write-up - Webkit Exploit (labs.mwrinfosecurity.com)
Abusing Safari's webarchive file format (community.rapid7.com)
Some harmless, old-fashioned fun with CSS (lcamtuf.blogspot.com)
VUPEN's Exploitation of IE10 on Windows 8 (CVE-2013-2551 / MS13-037 / Pwn2Own 2013) (vupen.com)
SSL: Intercepted today, decrypted tomorrow (news.netcraft.com)