cookie-bomb.md (1348B)
1 --- 2 title: "Cookie Bomb" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/hacking-with-cookies/cookie-bomb.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/hacking-with-cookies/cookie-bomb.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Cookie Bomb 14 15 A cookie bomb fills a user's cookie jar with enough data that subsequent requests to a target origin carry an oversized `Cookie` header. If an intermediary or application rejects those requests, the affected user can be locked out of the site while other users remain unaffected. Broad cookie scope can extend the impact to related subdomains.<sup>[[1]](#references)[[2]](#references)</sup> 16 17 HackerOne report 57356 provides a practical example of this user-specific denial of service.<sup>[[1]](#references)</sup> 18 19 For broader background on cookie-based attacks and browser limits, see *The Cookie Monster in Your Browsers*.<sup>[[2]](#references)</sup> 20 21 ## References 22 23 - [1] [HackerOne report 57356 - Cookie Bomb Denial of Service](https://hackerone.com/reports/57356) 24 - [2] [FileDescriptor - The Cookie Monster in Your Browsers](https://speakerdeck.com/filedescriptor/the-cookie-monster-in-your-browsers?slide=26)