Surf Jack - HTTPS will not save you
- From: lists@xxxxxxxxxxxxxxxxxx
- Date: 11 Aug 2008 09:30:37 -0000
Say hello to a new security tool called ?Surf Jack? which demonstrates a security flaw found in various public sites. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the Cookie secure flag.
Tool: http://surfjack.googlecode.com/
Short paper: http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf
Screencast: http://www.vimeo.com/1501107
This research was done independently from Mike Perry's[1], but it appears to be effectively the same thing.
[1] https://www.defcon.org/html/defcon-16/dc-16-speakers.html#Perry
--
Sandro Gauci
EnableSecurity
Web: http://enablesecurity.com/
- Prev by Date: Re: [funsec] Internet attacks against Georgian web sites
- Next by Date: [security bulletin] HPSBUX02356 SSRT080051 rev.1 - HP-UX Running ftpd, Remote Privileged Access
- Previous by thread: Re: [funsec] Internet attacks against Georgian web sites
- Next by thread: [security bulletin] HPSBUX02356 SSRT080051 rev.1 - HP-UX Running ftpd, Remote Privileged Access
- Index(es):