Surf Jack - HTTPS will not save you

From: lists@enablesecurity.com
To: bugtraq@securityfocus.com
Cc:
Subject: Surf Jack - HTTPS will not save you
Date:


Say hello to a new security tool called \u201cSurf Jack\u201d which demonstrates a security flaw found in various public sites. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the Cookie secure flag.

Tool: http://surfjack.googlecode.com/
Short paper: http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf
Screencast: http://www.vimeo.com/1501107

This research was done independently from Mike Perry's[1], but it appears to be effectively the same thing. 


[1] https://www.defcon.org/html/defcon-16/dc-16-speakers.html#Perry


--
Sandro Gauci
EnableSecurity
Web: http://enablesecurity.com/





Copyright © 1995-2021 LinuxRocket.net. All rights reserved.