Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
tlrobinson
on Aug 30, 2012
|
parent
|
context
|
favorite
| on:
Stripe CTF Writeup
The "secret" exposed in the exception page wasn't the actual flag, it was the secret used to sign session cookies. Once you had it you could modify your session cookie (typically to pose as a different user) and re-sign the cookie with the secret.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: