Identifying origin server of HTTP Cookies

Yngve Pettersen · 2011

HTTP Cookies, as originally defined by Netscape in [NETSC] andas later updated by [RFC2109] and [RFC2965] left unaddressed the issue of how to restrict which domains a server can set a cookie for, which is particularly a problem for servers hosted in top level domains have subdomains that are controlled by registries, not domain owners, e.g. co.uk and city.state.us domains. In such situations, unless the client uses some kind of domain black-list it is possible for a malicious server to set cookies that the client will send to all servers in a domain the attacker does not control, and these cookies may adversly affect the function of servers receiving them. The primary reason this is a problem is that the server receiving the cookie have no way of telling which server originally set it, and is therefore not able to reliably distinguish an invalid cookie from a valid cookie. This document proposes a new attribute, $Origin, that is associated with each cookie and sent in all the client's Cookie header in the request to the server. Servers recognizing the attribute may then check to see if the cookie was set by a server allowed to set cookies for the server, and if necessary ignore the cookie.

Read the paper · More papers on PaperTik