token). However, if the user continues to submit the token, then it is still
accepted by the server.
■■
In the worst cases, when a user clicks Logout, this fact is not communi-
cated to the server at all, and so the server performs no action whatso-
ever. Rather, a client-side script is executed that blanks the user’s
cookie, meaning that subsequent requests return the user to the login
page. An attacker who gains access to this cookie could use the session
as if the user had never logged out.
HACK STEPS
■
Do'stlaringiz bilan baham: