Hacker News new | ask | show | jobs
by Buge 3408 days ago
Maybe the cookie generation had some sort of vulnerability (such as length extension) and looking at the source code helped attackers locate it and exploit it.