Modern Browsers Are Undefended Against Cookie-based MITM Attacks Over HTTPS

DEAD7

Veteran
Supporter
Joined
Oct 5, 2012
Messages
51,489
Reputation
4,659
Daps
89,788
Reppin
Fresno, CA.
An advisory from CERT warns that all web-browsers, including the latest versions of Chrome, Firefox, Safari and Opera, have 'implementation weaknesses' which facilitate attacks on secure (HTTPS) sites via the use of cookies, and that implementing HSTS will not secure the vulnerability until browsers stop accepting cookies from sub-domains of the target domain. This attack is possible because although cookies can be specified as being HTTPS-specific, there is no mechanism to determine where they were set in the first place. Without this chain of custody, attackers can 'invent' cookies during man-in-the-middle (MITM) attacks in order to gain access to confidential session data.
 

acri1

The Chosen 1
Supporter
Joined
May 2, 2012
Messages
26,728
Reputation
4,758
Daps
122,742
Reppin
Detroit
Great.

I have a STRONG feeling that this is going to create more work for me down the line and I'll end up having to deploy a bunch of patches and shyt (as if I don't spend enough time doing that). :beli:
 
Top