A URL param is written straight into a cookie — then re-sent on every request until the server rejects the victim. Run it one step at a time, with your own target and payload.
LOW · CLIENT-SIDE DOS · $10K CLASS
progress node 1 / 6
Now:…
The Cookie Bomb — my first $10k
LOW · self-DoScookie bombing2019–2020
Sites write tracking params (gclid, utm_*, fbclid) straight into cookies. Send a ~4,000-char value → the browser re-sends it forever → the total header passes the server's 8,192 B cap → 400/414, victim bricked until they clear cookies. Earned the author $10k+ in a year.
1Pick a targetYOUR TURN
Hunt: "is this happening on other sites too?" — DevTools → Application → Cookies → look for gclid · utm_* · fbclid · dclid.
scan the target
Result✓ tracking found — gclid · utm_* · fbclid · dclid written to cookies. This site is a target.