Posted Nov 17, 2010 12:58 UTC (Wed) by DonDiego (subscriber, #24141)
[Link]
If you capture the insecure session cookie as described in the article, you don't need to enter a password.
Password takeover
Posted Nov 18, 2010 0:52 UTC (Thu) by bfields (subscriber, #19510)
[Link]
Try it. Go to facebook, and try to change your email address or your password without re-entering your password.
You'll find it doesn't let you, even though you've given it a session cookie. And that's by design....