2 ms·
I think you're deviating from the topic of protecting against the vulnerability HackerOne encountered: using a leaked session cookie. In their case, let's say
by jsploit 7y ago
I think you're deviating from the topic of protecting against the vulnerability HackerOne encountered: using a leaked session cookie.
In their case, let's say the victim analyst was based in the United States, and they have implemented your proposed session country-lock. I also happen to reside in the US, so the country-lock protection is worthless.
For other cases, you can _try_ to block proxies, VPNs, TOR, VPSs... but that in itself is perhaps a usability fail.