Cookie not marked as secure.
Unknown
Vulnerability Details
Ehy,
I have found a bug in twitter site but isn't in scope (the site) but I have decided to report because I think that you will consider it at our discretion! (Only hope for the hall of fame)
The site is from Twitter inc (I have check it with whois): investor.twitterinc.co
Issue: Cookie not marked as secure.
Cookie domain: investor.twitterinc.com
Coookies not flaged as secure (session cookie, so you have to enable the secure flag for theese cookies):
AMDA452F526X_SESSION (This cookie need the secure flag set, the other two, I don't know)
AMDA452F526X_BRIEFCASE
AMDA452F526X_PREVIEW
Thanks and regards,
Simone
Actions
View on HackerOneReport Stats
- Report ID: 15232
- State: Closed
- Substate: resolved
- Upvotes: 2