Description
Import variables from an array into the current symbol table.
If flags is not specified, it is assumed to be EXTR_OVERWRITE.
EXTR_OVERWRITE
If there is a collision, overwrite the existing variable.
The danger is that any state variables set before the extract($_...)'s can be overwritten arbitrarily. This also makes it essential that any and every variable is instantiated prior to any use.
Get on the same WiFi as your target, open up Wireshark and grab their HTTP communications.
To make this easier, there was/is a tool called Firesheep that can be used to hijack session cookies. The popularity of Firesheep caused many sites to enable HTTPS by default (e.g. Facebook did so).
HAHAHAHAAHAHAHAHAA
Steal a cookie, gain access.. WTF