Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

you have to be logged in for the request to work right?. if you are not logged in / don't have the cookie / session it won't work. so whats the problem? when your logged in you see all that stuff anyway why does it matter which flavor its in?

as long as your session is secured how will this work?



you make logged in user to visit specially crafted page, where you attack him with cross site <script> tag. and leak the data.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: