You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I didnt understand something, I know that Poisontap is works good by capturing non-HSTS website's cookies, I tried to reinject the cookie captured by poisontap on another pc by document.cookie on console and it worked fine but what about the major websites ? (twitter, facebook ...), does the backdoor configuration can do something ? Or are we totally safe on those website againts PS ?
I didnt correcty understand this :
allows attacker to remotely force the user to make HTTP requests and proxy back responses (GET & POSTs) with the user's cookies on any backdoored
Does this mean the attacker can get (example)twitter session cookies with the backdoor remotely ?
I dont see any twitter.com cookie on my poisontap.cookies.log
The text was updated successfully, but these errors were encountered:
theCake75
changed the title
Is poisontap effective with HT2S enabled website ?
Is poisontap effective with HSTS enabled website ?
Jun 13, 2017
Hello,
I didnt understand something, I know that Poisontap is works good by capturing non-HSTS website's cookies, I tried to reinject the cookie captured by poisontap on another pc by document.cookie on console and it worked fine but what about the major websites ? (twitter, facebook ...), does the backdoor configuration can do something ? Or are we totally safe on those website againts PS ?
I didnt correcty understand this :
Does this mean the attacker can get (example)twitter session cookies with the backdoor remotely ?
I dont see any twitter.com cookie on my poisontap.cookies.log
The text was updated successfully, but these errors were encountered: