Penetration Testing mailing list archives
Surf Jack - HTTPS will not save you
From: publists () enablesecurity com
Date: 11 Aug 2008 09:45:32 -0000
Say hello to a new security tool called Surf Jack which demonstrates a security flaw found in various public sites. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the Cookie secure flag. Tool: http://surfjack.googlecode.com/ Short paper: http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf Screencast: http://www.vimeo.com/1507697 This research was done independently from Mike Perry's[1], but it appears to be effectively the same thing. [1] https://www.defcon.org/html/defcon-16/dc-16-speakers.html#Perry -- Sandro Gauci EnableSecurity Web: http://enablesecurity.com/ ------------------------------------------------------------------------ This list is sponsored by: Cenzic Top 5 Common Mistakes in Securing Web Applications Get 45 Min Video and PPT Slides www.cenzic.com/landing/securityfocus/hackinar ------------------------------------------------------------------------
Current thread:
- Surf Jack - HTTPS will not save you publists (Aug 11)
- EIGRP route insertion tool JB (Aug 14)
- RE: EIGRP route insertion tool Leif Sawyer (Aug 14)
- Re: EIGRP route insertion tool Kurt Buff (Aug 14)
- EIGRP route insertion tool JB (Aug 14)