[2022.08.17] An Ana...
 
알림
모두 지우기

[2022.08.17] An Analysis of First-Party Cookie Exfiltration due to CNAME Redirections

(@jhlee2021)
글: 16
회원
주제 스타터
 

Abstract

DNS CNAME redirections, which can “steer” browser requests towards a domain different than the one in the request’s URI, are a simple and oftentimes effective means to obscure the source of a web object behind an alias. These redirections can be used to make third-party content appear as first-party content. The practice of evading browser security mechanisms through misuse of CNAMEs, referred to as CNAME cloaking, has been recently growing in popularity among advertisers/trackers to bypass blocklists and privacy policies.
While CNAME cloaking has been reported in past measure- ment studies, its impact on browser cookie policies has not been analyzed. We close this gap by presenting an in-depth character- ization of how CNAME redirections affect cookie propagation. Our analysis uses two distinct data collection samples (June and December 2020). Beyond confirming that CNAME cloaking continues to be popular, our analysis identifies a number of websites transmitting sensitive cookies to cloaked third-parties, thus breaking browser cookie policies. Manual review of such cases identifies exfiltration of authentication cookies to advertis- ing/tracking domains, which raises serious security concerns.

 

*발표자료: [Main Seminar] An Analysis of First-Party Cookie Exfiltration due to CNAME Redirections - NDSS2021.pdf

*논문: An Analysis of First-Party Cookie Exfiltration due to CNAME Redirections.pdf

 
게시됨 : 2022년 08월 17일 9:15 오전