Advertisement
Promo

Security threats Toolkit

Sans Institute warns of cookie-stealing threat

Tom Espiner ZDNet.co.uk

Published: 12 Sep 2008 15:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A tool to harvest cookies left from secure browser sessions can now be built, following the release of information on the CookieMonster exploit, security training organisation the Sans Institute has warned.

Information about the CookieMonster exploit has been published, the Sans Institute said, providing a way for hostile parties to retrieve information passed during HTTPS connections.

CookieMonster was developed by researcher and Riverbed developer Mike Perry, who gave a presentation on the subject at the Defcon security conference in August. Information about the tool and its ability to retrieve HTTPS session cookies in cleartext was released on Tuesday, warned Sans.

"If someone can place themselves so they see your web traffic, they can… force your browser to provide the saved cookies in a cleartext response," wrote Sans Institute handler David Goldsmith in a blog post.

According to Perry, who also publicised the vulnerability, CookieMonster is a man-in-the-middle attack that works by obtaining DNS responses and caching them. The exploit listens for port 443 connections, the default TCP port for HTTPS. It then uses the cache to map the IP to the domain name and add the IP to list of targets. When a request comes to port 80, used for non-encrypted traffic, CookieMonster injects HTTP images for the target sites. The victim's browser then transmits unencrypted cookies for the sites, which CookieMonster captures.

A number of attack vectors could be used by hackers, Perry warned, including Dan Kaminsky's DNS hijacking attack.

Read this

Q&A
Gartner: Authentication systems are 'fatally flawed'

Security analyst Jay Heiser gives his take on the rash of UK public-sector data losses and explains why authentication systems aren't up to scratch...

Read more +

Perry released details of the tool in his blog on Tuesday, and wrote that human-readable source code would be released in due course. He stressed that site administrators need to set cookies to be encrypted.

In a blog post on Friday, Perry added that, in addition to stealing insecure HTTPS cookies, CookieMonster also steals URL-based session ID details, which are used as a protection against cross-site request forgery. Stealing and using these details makes session theft attempts more likely to succeed.

Perry first published details of the vulnerability a year ago on the Bugtraq mailing list. However, in a blog post in August, Perry wrote that he had developed the exploit so vendors and developers would take the problem seriously.

"I waited a full year after submitting a detailed Bugtraq posting, as well as reporting the vulnerability to a major affected vendor, and still nothing happened," wrote Perry. "Without at least a demo, it seems that people are either not inclined to believe your vulnerability is real or not motivated to invest the effort in fixing it."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
4 out of 4 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters