Hacker News new | past | comments | ask | show | jobs | submit login

Tools like evilnginx proxy the traffic, then grab the auth token / cookie after a successful login. From there you can send the session tokens to something like necrobrowser to automatically do whatever you want with the account. The whole hack can happen in seconds.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: