
Episode 28: Surfin' with CSRFs
Critical Thinking - Bug Bounty Podcast
00:00
How to Use a Two Minute Window to Get a Cookie Reset
The two minute window was just sort of a catch all for very slow loading single sign on services. So I'm not exactly sure, you know, why they chose two minutes arbitrarily. And if you can still use it, it's very helpful for this technique. You've probably seen this before, but exploiting that where you trigger a login or a read login,. And what that will do is get the cookie reset - even if user has already gotten this out of session.
Transcript
Play full episode