Hey Kid,
To get user account passwords you'll need a dictionary file, and a lot of extra spare time on your hands. But that is assuming that you have the contents of the .htaccess file which you don't have access to.
You get no cookie.. Now go fuck your mother and have a beautiful day.
PS: Cached session ID's don't include plain-text passwords -- infact, they don't even include MD5/RSA or whatever the server's password encryption inside of the cookie. This is also assuming that you're actually able to hijack a session id -- which you aren't. Maybe if you have some kind of authoritive control for the routing tables belonging to the ISP of an existing member to your target paysite -- But then again, that person would have to be recently logged into the site for there to be any kind of cache.
|