3 ms·
Which only applies if you were to do it to systems that you aren't authorized to use it against. Simply creating and testing the code on your own servers is fa
by davis_m 13y ago
Which only applies if you were to do it to systems that you aren't authorized to use it against. Simply creating and testing the code on your own servers is far from unauthorized access. If it were anyone who had posted any PoC code would have been liable for anything that happened with their code.
- chc 13y agoYou seem to be talking about something different from what sullivanmatt and I were talking about. He said that collecting session IDs is not illegal, but posting them would be. That is the statement with which I was taking issue. At any rate, it certainly doesn't seem correct to say "it isn't illegal" as a blanket statement.
- davis_m 13y agoI was referring to calling it unauthorized access. If I do this to my own machines, which is how I wrote and tested this code, then it is entirely authorized. I would agree that collecting session ids on systems that you do not own or have legitimate access to is almost certainly illegal.
- jkrems 13y agoI think his statement strongly implied that he was speaking about session ids of site he doesn't own. If you own the site, saying that "using the session ids would be illegal" is a stretch, at least without qualifiers. So, pretty sure he was talking about other people's sites.