zlacker

[parent] [thread] 2 comments
1. ramchi+(OP)[view] [source] 2018-09-29 13:47:18
Is the cookie not associated to a specific IP? SSO systems would normally flag the mismatch if you try to connect to a website and pass an SSO cookie issued for a different IP, so sniffing cookies wouldn’t help all that much.
replies(1): >>thefou+Tl
2. thefou+Tl[view] [source] 2018-09-29 17:34:32
>>ramchi+(OP)
In the mobile space the IP address changes all the time, isn't it?
replies(1): >>ramchi+DZ
◧◩
3. ramchi+DZ[view] [source] [discussion] 2018-09-30 02:13:18
>>thefou+Tl
It's unlikely to change between the SSO login page and the application's login page, and it doesn't matter if it changes later on since the app can issue its own session cookie which isn't tied to an IP.
[go to top]