Would you like to react to this message? Create an account in a few clicks or log in to continue.

You are not connected. Please login or register

Microsoft latest security risk: "Cookiejacking"

3 posters

Go down  Message [Page 1 of 1]

QueenBee

QueenBee
 
 

BOSTON (Reuters) - A computer
security researcher has found a flaw in Microsoft Corp's widely used Internet
Explorer browser that he said could let hackers steal credentials to access
FaceBook, Twitter and other websites.

He calls the technique "cookiejacking."

"Any website. Any cookie. Limit is just your imagination," said
Rosario Valotta, an independent Internet security researcher based in Italy.

Hackers can exploit the flaw to access a data file stored inside the browser
known as a "cookie," which holds the login name and password to a web
account, Valotta said via email

Once a hacker has that cookie, he or she can use it to access the same site,
said Valotta, who calls the technique "cookiejacking."

The vulnerability affects all versions of Internet Explorer, including IE 9,
on every version of the Windows operating system.

To exploit the flaw, the hacker must persuade the victim to drag and drop an
object across the PC's screen before the cookie can be hijacked.

That sounds like a difficult task, but Valotta said he was able to do it
fairly easily. He built a puzzle that he put up on Facebook in which users are
challenged to "undress" a photo of an attractive woman.

"I published this game online on FaceBook and in less than three days,
more than 80 cookies were sent to my server," he said. "And I've only
got 150 friends."

Microsoft said there is little risk a hacker could succeed in a real-world
cookiejacking scam.

"Given the level of required user interaction, this issue is not one we
consider high risk," said Microsoft spokesman Jerry Bryant.

"In order to possibly be impacted a user must visit a malicious
website, be convinced to click and drag items around the page and the attacker
would need to target a cookie from the website that the user was already logged
into," Bryant said.

spy_lass4

spy_lass4

can i have dat cookie too? Cuz im starving to hack someone's accnt in fb? Hehehe...
Kini jud mga hackerz kaila b kaha n sila ug GABA?

babytwist

babytwist
 
 

mng hack ta... mhinumdum mo ani ni bratz hehe

QueenBee

QueenBee
 
 

spy_lass4 wrote:can i have dat cookie too? Cuz im starving to hack someone's accnt in fb? Hehehe...
Kini jud mga hackerz kaila b kaha n sila ug GABA?

kang kinsa'ng account man pud aber? hahaha..

QueenBee

QueenBee
 
 

babytwist wrote:mng hack ta... mhinumdum mo ani ni bratz hehe

..hahaha..mao jud Mare ug sa dihang nakatilaw og kasaba...hahaha...

spy_lass4

spy_lass4

QueenBee wrote:
spy_lass4 wrote:can i have dat cookie too? Cuz im starving to hack someone's accnt in fb? Hehehe...
Kini jud mga hackerz kaila b kaha n sila ug GABA?

kang kinsa'ng account man pud aber? hahaha..
hahaha,secret ky bsin blikan ko ug hack..laguttt!

babytwist

babytwist
 
 

ky sweetie nia na account AHEHEH

QueenBee

QueenBee
 
 

kay nganong i-hack man? sulunga nalang didto dad-i og sundang amow... Microsoft latest security risk: "Cookiejacking" 235184545

spy_lass4

spy_lass4

ajong buntag mahal n reyna... Microsoft latest security risk: "Cookiejacking" 4022035219

lau-lau to jamu mam. Nyahahaha
pero d n kelangan ihack aq sw33ti3..I have mur dan enuf to know him btr for now. NAKZ..

QueenBee

QueenBee
 
 

weeeeeeewwww...mura'g lami ang kabuntagon ron dah....dahan ka'g kape diha? ajaw na lang i-hack iyang account, i-hack nalang iyang heart..... Microsoft latest security risk: "Cookiejacking" 2038965257 Microsoft latest security risk: "Cookiejacking" 2038965257

spy_lass4

spy_lass4

nk2log sa 2ong party s higdaanan mam maong nkapangape ug sau...dali diay blak or latte?

Whewwww murag mglihod man ko ug hack mam..

QueenBee

QueenBee
 
 

..ug di makuha'g hack, kidnappa nalang...hahaha..

spy_lass4

spy_lass4

daghan kaayo guardiya...hahahaha...d kaya aq power..wl try naq dad an ug abusayap..jejeje..piz sw33ti3

QueenBee

QueenBee
 
 

hahaha...dad-i og mga kaliwat ni dagohoy..

spy_lass4

spy_lass4

nyahahahaha..cguro usa lang ka panun..

Sponsored content



Back to top  Message [Page 1 of 1]

Permissions in this forum:
You cannot reply to topics in this forum