|
|
|
|
|
by SahAssar
2733 days ago
|
|
> competent attackers will simply run their code from the victim's browser and session What do you mean? JS even on the same page can't read HTTPOnly cookies. If you are assuming that the browser has been hacked then it is pretty much game over regardless of what you use. |
|