4 ms·
Sure you do. Easy to confirm, just fire up a console on github.com and enter document.cookie. What runs there can run on the page in injected code. Sess cookie
by bl4k 16y ago
Sure you do. Easy to confirm, just fire up a console on github.com and enter document.cookie. What runs there can run on the page in injected code.
Sess cookie for github is km_ai
- pilif 16y agoI would assume that the session cookie is _github_ses which is the only one that's set as both httponly and secure and, by the way, doesn't appear in document.cookie