Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
JakeSkii
on Jan 27, 2024
|
parent
|
context
|
favorite
| on:
Rook to XSS: How I hacked chess.com with a rookie ...
Just to clarify, the PHPSESSID cookie was HttpOnly - I could extract the new value because I had overwritten it. Most of the cookies were set correctly (thankfully) however there was a lot of SPII stored in JS variables which I was able to get.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: