Session & IP Spoofing

From: pire pire (
Date: Tue Dec 02 2003 - 17:01:33 EST


I've found a vulnerability in a Web App which
gave me via an XSS the sessionID token.

I would like to replay this token. But the
session ID manager (on the server) seems to look
also to IP adresses.

So my question is: Is there a way to spoof my ip
address in order to replay the sessionID??

and some how spoof of my IP?!

If I replay the sessionid from my machine or an
other machine behind my NAT (same outside IP) it

Thanks a lot for your help


La messagerie gratuite des romands : 10 MO !!!
Profitez-en ! >>>


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:53:43 EDT