RSSAmplifier

· Jan 2, 2024

cookieJar

0
Sign in to vote or save

This page cannot be shown here. You can still read it on the original site — the toolbar below keeps your place in the directory.

a fun aspect of pentesting is finding interesting ways to get authenticated sessions running. usually, a session authentication relies on the user entering some kind of key (password) that corresponds to their user ID (username). however, in some cases an attacker can “revive” sessions using just the session cookies. i wrote cookieJar for exactly this purpose: extracting cookies from…

Read on /posts/cookiejar/

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.