Session Cookie Transmitted Over HTTP Due to Missing `Secure` Flag
Bug Report: Session Cookie Transmitted Over HTTP Due to Missing `Secure` Flag#
Target: play.[REDACTED], media.[REDACTED] (in-scope) CVSS v3.1 Score: 7.4 (High) CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Summary#
The authentication session cookie auth_v2, which is scoped to domain=.[REDACTED], is issued without the Secure flag. Two in-scope subdomains, play.[REDACTED] and media.[REDACTED], serve content over plain HTTP without redirecting to HTTPS. As a result, a network-positioned attacker (on the same LAN, a rogue access point, or via ISP-level interception) can capture the auth_v2 session cookie in cleartext HTTP traffic and impersonate the victim.
Impact#
- Account takeover: Stolen
auth_v2grants full authenticated access to the victim's [TARGET] account (subscription, watch history, personal information, payment-linked profile). - Passive attack: No user interaction beyond normal usage of the player or media features is required once the attacker is network-positioned.
- Scope of exposure: Because the cookie is
domain=.[REDACTED], it is sent to ALL*.[REDACTED]subdomains over HTTP, not just the two confirmed subdomains.
Affected Components#
| Host | HTTP Status | HTTPS Redirect | Notes |
|---|---|---|---|
play.[REDACTED] | 200 OK over HTTP | None | Video player SPA |
media.[REDACTED] | 200 OK over HTTP | None | Media delivery |
Cookie issued by: www.[REDACTED]/api/v1.0/accounts/login/by-anonymous and any authenticated endpoint.
Evidence: Cookie Attributes#
Response header from POST https://www.[REDACTED]/api/v1.0/accounts/login/by-anonymous:
set-cookie: auth_v2=[REDACTED]; domain=.[REDACTED]; expires=Mon, 22-Jun-2026 ...; path=/; HttpOnlyMissing attribute: `Secure`
HTTP response from play.[REDACTED] (no TLS negotiation, no redirect):
GET / HTTP/1.1
Host: play.[REDACTED]
HTTP/1.1 200 OK
Server: [REDACTED]-Edge
Content-Type: text/htmlSteps to Reproduce#
Prerequisites#
- Attacker positioned on the same network as the victim (LAN, Wi-Fi hotspot, or ISP-level).
- Victim has an account with an active
auth_v2session cookie.
Attack Flow#
Step 1: Victim visits https://www.[REDACTED] and authenticates. Cookie is set:
auth_v2=<session_token>; domain=.[REDACTED]; path=/; HttpOnlyStep 2: Victim later visits http://play.[REDACTED] or http://media.[REDACTED] (directly, via link, or via HTTP redirect from another page). The browser sends auth_v2 in cleartext since the Secure flag is absent and the subdomain is served over HTTP.
Step 3: Attacker captures the HTTP request via passive sniffing (tcpdump, Wireshark) or active MitM (arpspoof + mitmproxy):
GET / HTTP/1.1
Host: play.[REDACTED]
Cookie: auth_v2=[REDACTED] <- stolen in cleartextStep 4: Attacker replays the cookie against https://www.[REDACTED]:
curl -sk -H "Cookie: auth_v2=<stolen_token>" https://www.[REDACTED]/api/v1.0/account/profiles
# Returns victim's account profiles -> confirmed session takeoverPoC Commands#
# Confirm play.[REDACTED] serves HTTP without redirect
curl -v --max-time 10 "http://play.[REDACTED]/" 2>&1 | grep "< HTTP"
# Expected: HTTP/1.1 200 OK (no redirect to HTTPS)
# Confirm media.[REDACTED] serves HTTP without redirect
curl -v --max-time 10 "http://media.[REDACTED]/" 2>&1 | grep "< HTTP"
# Expected: HTTP/1.1 200 OK
# Confirm auth_v2 is issued without Secure flag
curl -si -X POST \
-H "Content-Type: application/json" \
-d '{}' \
"https://www.[REDACTED]/api/v1.0/accounts/login/by-anonymous" \
| grep -i "set-cookie"
# Expected: set-cookie: auth_v2=...; domain=.[REDACTED]; path=/; HttpOnly
# Note: NO "secure" keyword in the cookie attributesTools Used#
curl(v8.11.1): HTTP request crafting and header inspectiondig: DNS resolution
Activities Log#
| Time (UTC) | Activity |
|---|---|
| 2026-05-23 12:48 | HTTP status check on all in-scope hosts |
| 2026-05-23 12:48 | Response header inspection (Server, Set-Cookie, security headers) |
| 2026-05-23 12:55 | Confirmed play.[REDACTED] serves HTTP 200 with no redirect |
| 2026-05-23 12:52 | Confirmed auth_v2 cookie issued without Secure flag |
| 2026-05-23 12:55 | Confirmed media.[REDACTED] serves HTTP 200 with no redirect |
No accounts were accessed. No cookie was used for actual authentication. Only passive enumeration of HTTP headers was performed.
Recommended Fix#
- Add the
Secureattribute toauth_v2:Set-Cookie: auth_v2=...; domain=.[REDACTED]; path=/; Secure; HttpOnly; SameSite=Lax - Enforce HTTPS-only on
play.[REDACTED]andmedia.[REDACTED]with a 301 redirect from HTTP. - Add
Strict-Transport-Securityheader to all in-scope hosts.