Re: Session Sidejacking in facebook

0
51

Posted by adam on Jun 11

I was actually just kidding about releasing it to the list, but given the
nature of the vulnerability – the disclosure could have been a lot worse.

"Is this how it works in all social sites ?"

I've personally witnessed countless sites that authenticate a user based on
userID/token combination (and nothing else). Depending on the actual token
length, bruteforcing it is sometimes even possible.

"If the answer is yes, I will…

Source: Re: Session Sidejacking in facebook