Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
RE: Can you exploit this XSS?
From: Dawes, Rogan (ZA - Johannesburg) (rdawesdeloitte.co.za)
Date: Fri Nov 21 2003 - 01:59:29 CST
> P.S. Thanks to Mike Brownbill for pointing out that this is "minimal
> risk as stealing cookies from users which aren't logged in is quite
> simply futile" !!!
I get your cookie, you log in on the next step, and the cookie does not
change (for *MANY* applications). Now I have your cookie, and it is for an
All it means is that you need to wait for the user to authenticate before
ripping them off ;-)
Simply test that they have authenticated by visiting some URL that returns
different values based on an authenticated or unauthenticated cookie.
Important Notice: This email is subject to important restrictions, qualifications and disclaimers ("the Disclaimer") that must be accessed and read by clicking here or by copying and pasting the following address into your Internet browser's address bar: http://www.Deloitte.co.za/Disc.htm. The Disclaimer is deemed to form part of the content of this email in terms of Section 11 of the Electronic Communications and Transactions Act, 25 of 2002. If you cannot access the Disclaimer, please obtain a copy thereof from us by sending an email to ClientServiceCentreDeloitte.co.za.