hacktricks/src/pentesting-web/xs-search/cookie-bomb-+-onerror-xs-leak.md

7.0 KiB
Raw Blame History

Cookie Bomb + Onerror XS Leak

{{#include ../../banners/hacktricks-training.md}}

This technique combines:

  • Cookie bombing: stuffing the victims browser with many/large cookies for the target origin so that subsequent requests hit server/request limits (request header size, URL size in redirects, etc.).
  • Error-event oracle: probing a cross-origin endpoint with a