Captured admin sessions

2 run(s), newest first (in-memory + data/runs.jsonl). NOTE: rows from BROWSER-SUBMITTED are the real takeover — the forged assertion was posted from the victim's browser. Rows showing gw-no-vpn (404) are the server-side diagnostic only: gw is not on the VPN, so it cannot reach the target or capture the cookie.

whenasserted userACSJSESSIONIDwhoamiadmin gate
2026-10-07T15:24:44.681Zbofh ACCEPTED BBCC22CA1E726331135DEFD53C6B4005bofh 302 → /authenticate.action — ADMIN (WebSudo re-auth pending)
2026-10-07T15:22:05.655Zbofh gw-no-vpn (404) -- -

To capture the cookie, run the PoC from a VPN-connected host and POST it to /api/capture (or use the local /api/takeover).

← back