2 run(s), newest first (in-memory + data/runs.jsonl).
NOTE: rows from BROWSER-SUBMITTED are the real takeover — the forged assertion was posted from the victim's browser.
Rows showing gw-no-vpn (404) are the server-side diagnostic only: gw is not on the VPN, so it cannot reach the target or capture the cookie.
| when | asserted user | ACS | JSESSIONID | whoami | admin gate |
|---|---|---|---|---|---|
| 2026-10-07T15:24:44.681Z | bofh | ACCEPTED | BBCC22CA1E726331135DEFD53C6B4005 | bofh | 302 → /authenticate.action — ADMIN (WebSudo re-auth pending) |
| 2026-10-07T15:22:05.655Z | bofh | gw-no-vpn (404) | - | - | - |
To capture the cookie, run the PoC from a VPN-connected host and POST it to /api/capture (or use the local /api/takeover).