Broken Authentication - Brute Forcing a Stay Logged In Cookie

Опубликовано: 17 Июнь 2026
на канале: z3nsh3ll
1,075
39

Support This Channel
======================

Please like and subscribe, it means a lot!

Please buy me a coffee so I can continue to make content.
https://buymeacoffee.com/zenshell

Join our Discord
  / discord  


In this portswigger lab we see an example of a vulnerable stay logged in cookie. The cookie has no brute force protection mechanism in place and it is fairly easy to recreate the value of the cookie for different users since a static algorithm is used to create permanent cookie values.