I think this is it:
http://www.erratasec.com/sidejacking.zip
I wasn't doubting that Robert had done this. I was saying that it's already been done and he was just scripting it. Does this really count as security research?
I encourage other programmers to comment. My perception is that anyone who's written a bot could do this in one sitting.
Discussion on:
Message 9 of 1
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



