DEV Community

Discussion on: Sending cookies with Cross Origin (CORS) request

Collapse
 
zubairmohsin33 profile image
Zubair Mohsin

Hi. Thank you for your comment.

Can you share more about "Stealing cookies is not hard to make if the server has miss configuration, aka Apache/Nginx" ?

Currently I am setting cookies in a response from PHP using setcookie method. It would be helpful if you can share more about Apache/Nginx involvement here.

Thanks :)

Collapse
 
diek profile image
diek

Hi Zubair, there are tools that automatically steal cookies session. Search about that, usually those tools are included in kali linux or it can be manually installed in linux/unix.