• T156@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 days ago

    Or, session cookies. They don’t need special privilege to access, and if you grab all of someone’s cookies, you can probably get some valid session cookies for logged in accounts just by checking for some common domains in one/by keyword.

    From there, it would be trivial to get into email, social media, and other accounts to do other things with.