Sandro Gauci has posted a very interesting video demonstration about what he called Surf Jack.
Say hello to a new security tool called “Surf Jack” which demonstrates a security flaw found in many public sites. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the [...]