Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Heh, I wonder if they just quietly do that in the middle of a session

* GET bank.example.com/accounts

* GET bank.example.com/accounts/1

vpn disconnect

* GET bank.example.com/accounts/1/details <- 403 new IP, who dis?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: