logoalt Hacker News

notnullorvoidyesterday at 2:15 AM2 repliesview on HN

To be clear only the path and query parameters part of the url can change, the domain (or sub domain) stays intact.


Replies

sdf456yesterday at 11:58 AM

Even scarier to me than the vulnerability is that Fidelity (whom I personally think is a good bank and investment company) was using a third party that allowed injection that could potentially steal a whole lot of money, affect markets, ruin or terminate billions of lives, and affect the course of humanity. What the fuck.

show 3 replies
9rxyesterday at 7:03 PM

If it weren't already in the same domain you wouldn't be able to read a non-HttpOnly cookie anyway, so that's moot.