Skip to main content

#HITB2011AMS - IE Security Flaw Exposes Your Cookies

posted onMay 26, 2011
by hitbsecnews

An Italian security researcher has demonstrated an exploit in Microsoft’s web browser that could allow remote stealing of digital credentials, or cookies, The Register is reporting.

Rosario Valotta demonstrated his “cookiejacking” proof of concept last week at the Hack in the Box security conference in Amsterdam. His hack exposes a flaw in all current versions of Internet Explorer (IE) to steal session cookies that Facebook and other websites issue once a user has entered a valid password and corresponding user name.

The cookie acts as a digital credential that allows the user to access a specific account. This code specifically targets cookies issued by Facebook, Twitter and Google Mail, but Valotta said the technique can be used on virtually any website and affects all versions of Windows. “You can steal any cookie. There is a huge customer base affected (any IE, any Win version).”L33tdawg: All presentation materials from #HITB2011AMS is available for download here: http://conference.hitb.nl/hitbsecconf2011ams/materials/

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th