  1. TeemuVesala    6 years ago

    That actually misses something. Cookies should NOT include any sensitive information like username, password etc. Always during testing we should understand WHY they exist, and HOW they are used. At one "tester's chat" I used cookie to construct XSS against other users. It stored the color information, and by manipulating it, I managed to inject script to others.

  2. pranavks    6 years ago

    Yes, I agree with that. Thanks for letting me know the information. I am planning to create a second version of this mind-map and I will keep these point in my mind.

