4 ms·
Interesting, can you explain 'full control'?
by counterpartyrsk 3y ago
Interesting, can you explain 'full control'?
- crazygringo 3y agoYou can run any JavaScript. So you can show a popup saying the user needs to log in again, and then log their credentials on your own server instead.
- paledot 3y agoOr exfiltrate their session cookie, or post spam/phishing links on their behalf...
- sillysaurusx 3y agoSession cookies are generally not available to javascript. The latter is true though.
- None4U 3y agoPerhaps HttpOnly wasn't as prevalent back then?
- matsemann 3y agoYup, no CORS either, all protections relied on having proper CSRF-tokens, but with JS access one could read that token as well. My "hack" was mostly pretty harmless. Just did some layout changes to make my profile cooler. But the door was wide open for anything.