4 ms·
Not in any way a web dev, but couldn't an XSS on Lenovo's site make it possible to leak these?
by dankboys 4y ago
Not in any way a web dev, but couldn't an XSS on Lenovo's site make it possible to leak these?
- ElectricalUnion 4y ago> an XSS on Lenovo's site make it possible to leak these? Not if they're HttpOnly cookies. Then it requires actually compromise/mitm of the application server code to recover the cookies.