EXERCISE 2 — The five steps of the forged-transfer attack ========================================================== THE SEQUENCE: Step 1. The victim logs into yourbank.com. -> The browser stores a valid SESSION COOKIE for yourbank.com. Step 2. While still logged in, the victim visits evil.com (via a link, ad, or email). -> evil.com loads in the browser; the bank session is still active. Step 3. evil.com's hidden form AUTO-SUBMITS a POST to https://yourbank.com/transfer (its