3 ms·
I am guessing that they are able to bypass this restriction.
by itsnotvalid 15y ago
I am guessing that they are able to bypass this restriction.
- alecco 15y agoNo, the attack is against SSL and Man-in-the-Middle. They just make the browser send SSL requests with those cookies, and then guess the cookie (sent inside the SSL session).