Cookie Chaos: Exploiting Parser Discrepancies (Even @ydoow would be shocked)

No ratings

Presented at STEELCON 2025 by

Cookies were never meant to be secure. Bolted awkwardly onto HTTP, they’ve long been a source of confusion, inconsistency, and catastrophic vulnerabilities. Despite countless RFC fixes, things still fall apart. In this talk, I’ll uncover how fundamental flaws in cookie parsing continue to enable real-world bypasses of core security mechanisms. I’ll introduce previously unpublished techniques and new classes of cookie-based attacks that exploit discrepancies between client-side and server-side interpretations—allowing attackers to compromise session integrity at scale. To wrap up, I’ll release an open-source toolkit to help security researchers detect and exploit these flaws in the wild. If you think you know cookies, think again. This talk will uncover the most subtle RFC flaws.