Penetration Testing mailing list archives

Surf Jack - HTTPS will not save you


From: publists () enablesecurity com
Date: 11 Aug 2008 09:45:32 -0000

Say hello to a new security tool called “Surf Jack” which demonstrates a security flaw found in various public sites. 
The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the Cookie 
secure flag.

Tool: http://surfjack.googlecode.com/
Short paper: http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf
Screencast: http://www.vimeo.com/1507697

This research was done independently from Mike Perry's[1], but it appears to be effectively the same thing. 


[1] https://www.defcon.org/html/defcon-16/dc-16-speakers.html#Perry


--
Sandro Gauci
EnableSecurity
Web: http://enablesecurity.com/

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes in 
Securing Web Applications
Get 45 Min Video and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------


Current thread: