AOH :: HP Unsorted S :: BX4086.HTM

Surf Jack - HTTPS will not save you



Surf Jack - HTTPS will not save you
Surf Jack - HTTPS will not save you



Say hello to a new security tool called =93Surf Jack=94 which demonstrates a security flaw found in various public sites. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the Cookie secure flag.

Tool: http://surfjack.googlecode.com/
Short paper: http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf
Screencast: http://www.vimeo.com/1501107

This research was done independently from Mike Perry's[1], but it appears to be effectively the same thing.


[1] https://www.defcon.org/html/defcon-16/dc-16-speakers.html#Perry


--
Sandro Gauci
EnableSecurity
Web: http://enablesecurity.com/ 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.