Sans Institute warns of cookie-stealing threat

By Tom Espiner, ZDNet UK
Monday, September 15, 2008 05:22 AM

A tool to harvest cookies left from secure browser sessions can now be built, following the release of information on the CookieMonster exploit, security training organization the Sans Institute has warned.

Information about the CookieMonster exploit has been published, the Sans Institute said, providing a way for hostile parties to retrieve information passed during HTTPS connections.

CookieMonster was developed by researcher and Riverbed developer Mike Perry, who gave a presentation on the subject at the Defcon security conference in August. Information about the tool and its ability to retrieve HTTPS session cookies in cleartext was released on Tuesday, warned Sans.

"If someone can place themselves so they see your Web traffic, they can...force your browser to provide the saved cookies in a cleartext response," wrote Sans Institute handler David Goldsmith in a blog post.

According to Perry, who also publicized the vulnerability, CookieMonster is a man-in-the-middle attack that works by obtaining DNS responses and caching them. The exploit listens for port 443 connections, the default TCP port for HTTPS. It then uses the cache to map the IP to the domain name and add the IP to list of targets. When a request comes to port 80, used for non-encrypted traffic, CookieMonster injects HTTP images for the target sites. The victim's browser then transmits unencrypted cookies for the sites, which CookieMonster captures.

A number of attack vectors could be used by hackers, Perry warned, including Dan Kaminsky's DNS hijacking attack.

Perry released details of the tool in his blog on Tuesday, and wrote that human-readable source code would be released in due course. He stressed that site administrators need to set cookies to be encrypted.

In a blog post on Friday, Perry added that, in addition to stealing insecure HTTPS cookies, CookieMonster also steals URL-based session ID details, which are used as a protection against cross-site request forgery. Stealing and using these details makes session theft attempts more likely to succeed.

Perry first published details of the vulnerability a year ago on the Bugtraq mailing list. However, in a blog post in August, Perry wrote that he had developed the exploit so vendors and developers would take the problem seriously.

"I waited a full year after submitting a detailed Bugtraq posting, as well as reporting the vulnerability to a major affected vendor, and still nothing happened," wrote Perry. "Without at least a demo, it seems that people are either not inclined to believe your vulnerability is real or not motivated to invest the effort in fixing it."


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Output local group membership on Windows Server

Windows Server

Command line skills for Windows Servers are essential to deliver information without wasting time. Here's how an old tool and a new tool can help.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web