Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Surf Jacking - hijacking HTTPS sessions
Search Topic:
Uniqs:
379
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 20 Aug 2008 »
« Microsoft Security Bulletin(s) for August 12 2008  
AuthorAll Replies
-


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

reply to EGeezer
Re: Surf Jacking - hijacking HTTPS sessions

Interesting. Thanks for posting.

While examining cookies recently, I notice that there is a flag "https only", but it is FALSE on all of my cookies, including those from banking sites. I think banks need to reconsider whether to set this flag.

My own practice is pretty safe. I use firefox. But I use a separate profile for banking and similar functions. Typically, for banking, I'll open a browser for my banking profile, do the transaction, then close that browser. I normally have another browser running for non-critical tasks (such as visiting dslreports.com). With firefox it is possible to have two browser instances at the same time, but using different profiles. If I needed to do an extra lookup during the banking, I would not do that with my banking profile browser.

I use the separate browser profile mainly because of my concern about cookies perhaps being stolen with a new cross site scripting bug. While I was not aware of the possibility of the "side jacking", it is just the kind of possibility that I wanted to protect against.

On the other hand, the exploit as described in your linked article sounds a bit improbable. A lot of things have to come together at the same time in order to get the trick to work. My guess is that cybercriminals can find easier ways than this, so I'm doubtful that it will be used much except for proof of concept tests.
--
AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1


EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage


1 edit
  Surf Jacking is an interesting concept that's well explained in a Tech Republic blog article. At the least, the concept provides some reason for increased awareness of the risks of using untrusted networks and browsing HTTP (non-SSL) while a HTTPS (SSL)session is still open.

said by article :

... almost a year ago Robert Graham introduced “Side Jacking” at Black Hat 2007. It was such an interesting concept that (the article author) covered it in the article, “Can your wireless network be sidejacked?” Side jacking is a clever way of stealing HTTP session cookies, allowing the attacker to actually hijack a HTTP session without knowing any log on credentials. That was a year ago and now there are proof-of-concept attack tools to do the same thing with SSL connections. ...
Article here.
--
The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well-meaning but without understanding. -- Justice Louis D. Brandeis
Forums » Up and Running » Security » SecuritySecurity Software Updates - 20 Aug 2008 »
« Microsoft Security Bulletin(s) for August 12 2008  


Friday, 04-Dec 01:15:58 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [162] Comcast Releasing Promised Usage Meter
· [140] Avast Antivirus Has Gone Mad
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [98] Comcast Makes NBC Universal Acquisition Official
· [82] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [64] Broadband Killed The Game Console
· [64] Sprint Defuses GPS Privacy Media Bomb
· [55] Rogers Unveils The ISP Dream Model
Most people now reading
· False positive in Avast! or is it real? [Security]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· Maximizing Rogue DPS for ToC/ToGC (3.x) [World of Warcraft]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· [Business] how to bridge a smc 8014 business class modem [Comcast HSI]
· Windows 7 boot manager editing questions [Microsoft Help]
· What the heck is going on in SoCal - Part 3 [Road Runner]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [TWC] Audio/Video outage in Brooklyn [Time Warner Cable TV/Voice]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]