Sorgun:

If you have captured successfully GX cookie then it should work no matter you are using same PC or different PC in same or different network.

Idea behind this is as long as you have unsecure GX cookie you would be able to replay this attack.

Assume you have captured unsecure GX cookie and you are loged in to your Gmail account. Be at the page of your Gmail account open Cookie Editor and replace GX cookie and being there on that page in Address bar you would have to type mail.google.com and press enter.

This method will not work if victim has also enabled "Always use https" option from Gmail mail account settings.

I've checked this methods works fine till now....

As per my findings for yahoo you have to replace cookie B , Y and T and type mail.yahoo.com on the same address bar.