3 ms·
May be with an ETag: https://en.wikipedia.org/wiki/HTTP_ETag https://en.wikipedia.org/wiki/HTTP_ETag
by vmorgulis 10y ago
May be with an ETag:
https://en.wikipedia.org/wiki/HTTP_ETag https://en.wikipedia.org/wiki/HTTP_ETag
- bbcbasic 10y agoETag is for notifying that content has been updated, so how would you use the mechanism to log someone in?
- niftich 10y agoYou can exploit the fact that HTTP caching sends the ETag back and forth. A server can set a crafted ETag and basically use it as a session ID. See [1][2] [1] http://security.stackexchange.com/questions/12679/how-can-i-prevent-tracking-by-etags http://security.stackexchange.com/questions/12679/how-can-i-... [2] https://github.com/lucb1e/cookielesscookies/blob/master/index.php https://github.com/lucb1e/cookielesscookies/blob/master/inde...