Updated: 06/03/2002; 02:20:08.
My Tech Radio .Com
Broadcasting the latest tech tips and PC news straight to your desktop. Edited by Steven McDonald.
        

12 February 2002

__________________________________________________________________________

New 'Cookie' Security Exploit!

An independent network security researcher has uncovered a new way to steal the secret browser cookies of Web surfers with the help of Internet servers that were never intended to communicate with browser software.

The exploit, described by a researcher who uses the handle "Obscure" and posted on the Eye On Security Web (EOS) site, relies on common Internet server software other than Web servers that can "echo" hijacked submissions from HTML forms.

In a demonstration of the exploit, which Obscure calls the Extended HTML Form Attack, a POP3 (post office protocol) e-mail server at Ebay was used to divulge the browser cookies of users who had visited the auction giant's Web site.

As delivered by some Web sites, browser cookies may contain such private information as user IDs and passwords.

Read The Full Story: http://www.technews.com/news/02/174306.html


12:29:03 AM    


© Copyright 2002 Steven McDonald.
 
February 2002
Sun Mon Tue Wed Thu Fri Sat
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28    
Jan   Mar


Click here to visit the Radio UserLand website.

Click to see the XML version of this web page.

Site Meter