View Single Post
  #3 (permalink)  
Old 04-02-2007, 12:09 PM
jholder jholder is offline
Former Zimbran
 
Posts: 5,606
Default

We have done a little investigating on this issue with our toolkit, to see the impact, if any.

The kicker would be to get the auth token they'd need to hijack the domain/site that mail is hosed on since the browser will only send to the site where the cookie was set.

There's really only one way to get the auth token-
You need a authorized username and password.

If your site is hijacked, I think you have bigger worries, then just the toolkit
Reply With Quote