1 / 4

Hacking social media sites become easier by exploiting cooki

http://www.houstonianonline.com/news/hacking-social-media-sites-become-easier-by-exploiting-cookies-1.2819362#.UVOKURenoXu Internet users may want to keep an eye on their cookie jar, because a new discovery has linked cookies with hacked social media accounts. Internet researcher Rishi Narang discovered a flaw in the way cookies are used by Twitter, LinkedIn, Microsoft Outlook/Live, and Yahoo. According to Australia’s SC Magazine, Narang found that cookies can be “stolen and used” in a “session fixation” attack. A session fixation is a method of hacking that tricks a victim into using a session identifier chosen by the attacker. If successful, it represents the simplest method with which a valid session identifier can be obtained. One student at SHSU however didn’t find the exploit a big deal. “If I got hacked like that, I wouldn’t really care,” senior student Christopher Valva said. “It’s just a Twitter account. It’s not my entire life.” See this video: http://www.dailymotion.com/video/xxyx4f_hass-associates-online-scam-du-jour-they-re-creative-everywhere-so-beware-deviantart_news#.UVGzshdTDCY Read this: http://www.linkedin.com/groups/Hass-Associates-Online-Cyber-Review-4883972

scarlethugh
Télécharger la présentation

Hacking social media sites become easier by exploiting cooki

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. International Hass and Associates News Blog Hacking social media sites become easier by exploiting cookies

  2. Read more: http://www.houstonianonline.com/news/hacking-social-media-sites-become-easier-by-exploiting-cookies-1.2819362#.UVOKURenoXu Internet users may want to keep an eye on their cookie jar, because a new discovery has linked cookies with hacked social media accounts.Internet researcher Rishi Narang discovered a flaw in the way cookies are used by Twitter, LinkedIn, Microsoft Outlook/Live, and Yahoo. According to Australia’s SC Magazine, Narang found that cookies can be “stolen and used” in a “session fixation” attack.A session fixation is a method of hacking that tricks a victim into using a session identifier chosen by the attacker. If successful, it represents the simplest method with which a valid session identifier can be obtained.One student at SHSU however didn’t find the exploit a big deal.“If I got hacked like that, I wouldn’t really care,” senior student Christopher Valva said. “It’s just a Twitter account. It’s not my entire life.”

  3. If an attacker can intercept cookies while the user is logged in, the attacker could effectively convince the website that their browser is the original user’s browser, gaining “unfettered access” to your account. Not even a password change could keep the attacker out.It goes without saying that this form of hacking only works if the user is logged in, because the cookie is deleted when the user logs out. LinkedIn is an exception however, because sometimes it retains a user’s cookie for three months.Rishi Narang evaluated about how this new exploit affects session management security in his blog.“Ever since the session management grew complex,” Narang wrote, “its correlation with security has gone for a toss.”

  4. SC Magazine also reported that they were able to duplicate Narang’s method to test this exploit’s effectiveness.According to their test, “[They were] able to access various Twitter accounts by inserting the respective alphanumeric‘auth_token’ into locally stored Twitter cookies using the Cookie Manager browser extension.”The process of intercepting cookies is tedious and troublesome, but it is hardly beyond the scope of an experienced hacker’s ability. Users of any site should take heed and log out after their session. Check this out: http://www.dailymotion.com/video/xxyx4f_hass-associates-online-scam-du-jour-they-re-creative-everywhere-so-beware-deviantart_news#.UVGzshdTDCY http://www.linkedin.com/groups/Hass-Associates-Online-Cyber-Review-4883972

More Related