Client-Side Cookie Tampering


Cookie TamperingA cookie is a small snippet of information used by websites and web applications for user session tracking. They are often unencrypted (though cookie encryption is becoming more prevalent) and contain information created by web servers that is then stored on users’ web browsers. Whenever a user goes to a website that had previously set cookies in the user’s browser, the web server exchanges specific sets of data with the browser, usually for the purpose of facilitating easier log-in to a website or application, or returning the user to the same section of the web page that was previously being viewed, to name a few examples of cookie functionality.

Cookies can remain persistent until a preset date, or only valid for one user session until log-out. They can also be deleted by the user for additional privacy and to avoid revealing to one website that a user also visited (or has an account with) another website.

Client-side cookie tampering is a method of tampering with the information stored on a user’s web browser and manipulating it to be used in malicious ways, such as hijacking a user’s session on a website or application. Such tactics can be used to assist in account takeover, impersonation, and fraud. In the context of bot detection, cookies are not considered to be a reliable marker of a visitor’s identity or humanity since they can easily be tampered with on the client side to carry out malicious activities.

Radware’s Application Security Analyzer

Is Your Website Secure Against Bot & API Attacks? Find Out Now

已经是客户?

无论您需要支持或更多服务,还是需要解答有关我们产品和解决方案的问题,我们都会随时提供帮助。

公司地点
马上从知识库获得答案
获得免费在线产品培训
联系Radware技术支持部
加入Radware客户计划

参与社交

联系专家并加入有关Radware技术的对话。

Blog
安全研究中心
CyberPedia