stealing web browser cookies
play

Stealing Web Browser Cookies ben-holland.com Whats a cookie? Web - PowerPoint PPT Presentation

Stealing Web Browser Cookies ben-holland.com Whats a cookie? Web 2.0 Cookies provide state Examples: Items in shopping cart AuthenFcaFon! Cookies Passwords! Username + Password = Cookie If I know your authenFcaFon


  1. Stealing Web Browser Cookies ben-holland.com

  2. What’s a cookie?

  3. Web 2.0 – Cookies provide state Examples: • Items in shopping cart • AuthenFcaFon!

  4. Cookies ≥ Passwords! • Username + Password = Cookie • If I know your authenFcaFon cookie value I don’t need your password! • SomeFmes cookies don’t expire for a really long Fme…

  5. How can I get your cookies? • Packet sniffing (wiretapping) – Wired networks – Wireless networks • (IASTATE vs eduroam) – HTTP vs. HTTPS – hUps://www.cookiecadger.com/ – hUps://github.com/benjholla/tssk

  6. How can I get your cookies? • XSS (Cross Site ScripFng) AUacks – How about you just send me your cookies… – HTTP Only Flag

  7. How can I get your cookies? • Client Side AUacks – Browsers store cookies in a file… – hUps://github.com/benjholla/CookieMonster

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend