Denial of Service using Cookie Bombing
Denial of Service (DoS)
While observing headers and response of the first request which was simple GET request to homepage WWW.EXAMPLE.COM, it came to my mind that why not check hidden get parameters?
https://medium.com/@ronak_9889/denial-of-service-using-cookie-bombing-55c2d0ef808c