People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!
Version of a cookie was required. Many servers will downgrade their cookie parser to an older type if the version is found. This was used for WAF bypass techniques.$Version in the cookie header because they don't support it. So, you're able to set this from JavaScript.$Version attribute to downgrade the parser, the ENTIRE quoted string would be sent back, including the PHPSESSID. $Version=1,session="deadbeef in it. Notice the double quote at the beginning of it that isn't closed.dummy=qz". This finishes the quoted cookie.