Microsoft latest security risk: "Cookiejacking"

Airbot

----------------------
VIP
SF Team
Local time
9:11 AM
Messages
18,396
A computer security researcher has found a flaw in Microsoft Corp's widely used Internet Explorer browser that he said could let hackers steal credentials to access FaceBook, Twitter and other websites.
He calls the technique "cookiejacking."


"Any website. Any cookie. Limit is just your imagination," said Rosario Valotta, an independent Internet security researcher based in Italy.
Hackers can exploit the flaw to access a data file stored inside the browser known as a "cookie," which holds the login name and password to a web account, Valotta said via email


Once a hacker has that cookie, he or she can use it to access the same site, said Valotta, who calls the technique "cookiejacking."
The vulnerability affects all versions of Internet Explorer, including IE 9, on every version of the Windows operating system.


To exploit the flaw, the hacker must persuade the victim to drag and drop an object across the PC's screen before the cookie can be hijacked
.
more
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
IE Flaw Could Allow Hackers Access to your social networking accounts

networkworld said:
Regardless of the version of Windows you use, if you also use any versions of Microsoft's Internet Explorer, then you might not want to do any drag-and-dropping within your IE browser, or you might be done in by "cookiejacking." It's not the CookieMonster or Firesheep, but there is a zero-day hole in IE that allows an attacker to steal any session cookies from any website.
At the Hack In A Box conference in Amsterdam, Italian security researcher Rosario Valotta demonstrated a cookiejacking attack. A session cookie holds information like your username and your password. Once those cookies are stolen, it allows an attacker to access wherever the victim is logged in like Gmail, Facebook, Twitter or other online accounts.

Read more ...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Professional x64 SP1 ; Windows Server 2012 R2 Standard
CPU
Intel Core i5 2400 @ 3.10GHz
Motherboard
Foxconn H67MP-S/-V/H67MP
Memory
8.0GB DDR3 @ 665MHz (2GBx4)
Graphics Card(s)
AMD Radeon HD 6870
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AOC 2243W & SMB1930NW
Screen Resolution
1440x900 & 1920x1080
Hard Drives
977GB Seagate ST31000524AS ATA Drive (SATA)
250GB WD iSCSI attached Drive
PSU
750W Gaming PSU
Case
Novatech Night
Cooling
Fan
Keyboard
Dell Standard PS/2 Keyboard
Mouse
R.A.T 07 Gaming Mouse
Internet Speed
Download: 10 Mbps Ping: 30ms Upload: 0.81 Mbps
Browser
Google Chrome
Other Info
Optiarc DVD RW AD-5260S ATA Device
Interesting
 

My Computer

Computer Manufacturer/Model Number
Brewed
OS
Microsoft Windows 7 Ultimate: x64 (SP1)
CPU
Intel® Core™ i5-2500K Processor
Motherboard
ASUS P8Z68-V PRO
Memory
Kingston DDR3 HyperX 1600MHz 8GB
Graphics Card(s)
ASUS GTX 560 TI DirectCU II 900MHz
Sound Card
Realtek® ALC892 8-Channel High Definition Audio CODEC
Monitor(s) Displays
ACER LCD P246HBD 1920x1080 (24") - Dell 1280x800
Screen Resolution
ACER LCD P246HBD ~ [1920X1080] - DELL ~ [1280x800]
Hard Drives
500 GB WD Caviar SE116 7200rpm SATA2
PSU
Corsair 750W Power Supply
Case
Coolermaster CM Scout
Cooling
Zalman FS-C77 Fatal1ty CPU Cooler
Keyboard
Logitech G15
Mouse
Coolermaster Sentinel Advanced
Internet Speed
[↓ 10 MB/s DL] [↑ 1 MB/s UL]
Other Info
- ROCCAT™ Kave – Solid 5.1 Surround Sound Gaming Headset
- Not overclocking
This doesn't apply to any other browser, does it? Hopefully Microsoft will release a security update addressing this.
 

My Computer

Computer type
PC/Desktop
OS
10 Home x64
CPU
Intel Core i5 4670K
Motherboard
Gigabyte GA-Z87-D3HP
Memory
Corsair XMS3 8GB DDr3 1600MHz
Graphics Card(s)
Sapphire NITRO Radeon R9 Fury
Sound Card
Asus Xonar DX
Monitor(s) Displays
Acer H236HLbmjd
Screen Resolution
1920x1080
Hard Drives
Force GS 128GB - Seagate 320GB - WD Caviar Black 1TB - WD Caviar Blue 500GB
PSU
EVGA SuperNOVA 650 P2
Case
Silverstone Raven 3 RV03B-W
Keyboard
Topre Realforce 104UG-HiPro
Mouse
Mionix Naos 7000
Internet Speed
76/4 On a good day
Antivirus
SmartScreen
Browser
Internet Explorer 11
No Looks like it doesn't - Hopefully they do bring an Update

Josh
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Professional x64 SP1 ; Windows Server 2012 R2 Standard
CPU
Intel Core i5 2400 @ 3.10GHz
Motherboard
Foxconn H67MP-S/-V/H67MP
Memory
8.0GB DDR3 @ 665MHz (2GBx4)
Graphics Card(s)
AMD Radeon HD 6870
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AOC 2243W & SMB1930NW
Screen Resolution
1440x900 & 1920x1080
Hard Drives
977GB Seagate ST31000524AS ATA Drive (SATA)
250GB WD iSCSI attached Drive
PSU
750W Gaming PSU
Case
Novatech Night
Cooling
Fan
Keyboard
Dell Standard PS/2 Keyboard
Mouse
R.A.T 07 Gaming Mouse
Internet Speed
Download: 10 Mbps Ping: 30ms Upload: 0.81 Mbps
Browser
Google Chrome
Other Info
Optiarc DVD RW AD-5260S ATA Device
When something like this comes along I do wonder how man people Microsoft has checking, verifying, and fixing the problem.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
This method of hijacking confidential information, using clever 'attachments' as bait, just serves as another excellent reminder to be very cautious when using the internet. We already know that attachments (in any form) are highly suspect for carrying malware of all kinds -- we now are aware of yet another method/form of using them to steal our confidential information. As someone who has had funds stolen out of my bank account by a PayPal hijacker, I am especially appreciative of this warning!
 

My Computer

Computer Manufacturer/Model Number
HP Pavillion dv5t (generation 1)
OS
Vista 64 bit and 32 bit (SP2)
CPU
Intel(R) Core(TM)2 Duo Processor T9400 (2.53 GHz
Memory
4GB DDR2 System Memory (2 Dimm)
Graphics Card(s)
512 MB NVIDIA GeForce 9600M GT
Monitor(s) Displays
15.4" diagonal WSXGA+ High-Definition HP BrightView Widescre
Screen Resolution
1680 x 1050
Hard Drives
320GB 5400RPM SATA Hard Drive with HP ProtectSmart Hard Drive Protection
Keyboard
Built-in HP
Mouse
Built in - Synaptics TouchPad V6.5 on PS/2 Port
Internet Speed
Max
Other Info
~ Intel Next-Gen Wireless-N Mini-card w/Bluetooth ~ Blu-Ray ROM DVD+/-R/RW ~ Integ. HDTV Hybrid Tuner ~ 12 Cell Battery ~ MS Office (Home Premium) 2007 ~
I don't get this bit:
Microsoft is not too worried about this zero-day hole in all versions of IE. Microsoft spokesman Jerry Bryant said, "Given the level of required user interaction, this issue is not one we consider high risk. In order to possibly be impacted a user must visit a malicious website, be convinced to click and drag items around the page and the attacker would need to target a cookie from the website that the user was already logged into."

The guy who demonstrated it created a Facebook app, which you have to drag and drop to play... and surely the targeted cookie would be facebook in that case? Back when I used facebook, judging from the amount of crap that got posted to my wall, everyone was always playing whatever games, with hardly a care about security/malware. Seems to be this is a very valid attack.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Medion Erazer (note to self: insert model number) - with custom additions
OS
Windows 10 Pro x64
CPU
Intel Core i5 7400 @ 3.00GHz
Motherboard
OEM supllied with PC
Memory
8GB 2133Mhz DDR4 (OEM supplied)
Graphics Card(s)
Gygabyte Windforce GTX 1050Ti (Factory Overclocked)
Sound Card
Realtek
Monitor(s) Displays
Acer Al1980 + HKC
Screen Resolution
1360*768(HKC) / 1280*1024(Acer)
Hard Drives
1TB Toshiba
1TB WD Caviar Green
120GB Samsung Evo 840
PSU
OEM supplied (no power rating on case)
Case
OEM Supplied
Cooling
Stock
Keyboard
Logitech Wireless
Mouse
Logitect Wireless
Internet Speed
40Mb/s Down 10Mb/s Up
Antivirus
Defender
Browser
Firefox
A computer security researcher has found a flaw in Microsoft Corp's widely used Internet Explorer browser that he said could let hackers steal credentials to access FaceBook, Twitter and other websites.
He calls the technique "cookiejacking."

I know i'll get jumped on... But this is a bad thing??? Nah...

I live for the day sites like facebook and Twitter are shut down... ;)

<rant> My kids, like so many others, have lost the ability to communicate face to face, walk around like zombies and sleep with their iPods and iPhones in their hands.. They will check and update their facebook wall in preference to visiting the bathroom... When you're trying to watch TV the damn devices are making noises every 2 minutes as things re updated... <end rant>
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Made
OS
Linux Mint 17 Cinnamon | Win 7 Ult x64
CPU
Intel I7-3770K @ 4.2ghz
Motherboard
ASRock Extreme 4
Memory
32GB G-Skill C10Q
Graphics Card(s)
EVGA GTX 670 2GB SC
Sound Card
Creative Fatality ExtremeGamer
Monitor(s) Displays
LG E2742V x 2
Screen Resolution
1920x1080
Hard Drives
256GB Vertex 4 SSD
2TB Seagate ST2000DM001
1TB Seagate ST1000DM003
PSU
Corsair HX 650
Case
HAF 932 advanced
Cooling
Corsair H100i liquid cooler
Keyboard
Logitech Wireless
Mouse
Logitech Wireless
Internet Speed
OptusNet NBN 100/40
Antivirus
Malwarebytes
Browser
Firefox 30
Other Info
Router: Sagemcom F@st 3846 Crippled by Optus.
A computer security researcher has found a flaw in Microsoft Corp's widely used Internet Explorer browser that he said could let hackers steal credentials to access FaceBook, Twitter and other websites.
He calls the technique "cookiejacking."

I know i'll get jumped on... But this is a bad thing??? Nah...

I live for the day sites like facebook and Twitter are shut down... ;)

<rant> My kids, like so many others, have lost the ability to communicate face to face, walk around like zombies and sleep with their iPods and iPhones in their hands.. They will check and update their facebook wall in preference to visiting the bathroom... When you're trying to watch TV the damn devices are making noises every 2 minutes as things re updated... <end rant>
How old are they?
 

My Computer

Computer Manufacturer/Model Number
HP p7-1254
OS
7 64 bit Home Premium
A computer security researcher has found a flaw in Microsoft Corp's widely used Internet Explorer browser that he said could let hackers steal credentials to access FaceBook, Twitter and other websites.
He calls the technique "cookiejacking."

I know i'll get jumped on... But this is a bad thing??? Nah...

I live for the day sites like facebook and Twitter are shut down... ;)

<rant> My kids, like so many others, have lost the ability to communicate face to face, walk around like zombies and sleep with their iPods and iPhones in their hands.. They will check and update their facebook wall in preference to visiting the bathroom... When you're trying to watch TV the damn devices are making noises every 2 minutes as things re updated... <end rant>
How old are they?

15, 16, and 20
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Made
OS
Linux Mint 17 Cinnamon | Win 7 Ult x64
CPU
Intel I7-3770K @ 4.2ghz
Motherboard
ASRock Extreme 4
Memory
32GB G-Skill C10Q
Graphics Card(s)
EVGA GTX 670 2GB SC
Sound Card
Creative Fatality ExtremeGamer
Monitor(s) Displays
LG E2742V x 2
Screen Resolution
1920x1080
Hard Drives
256GB Vertex 4 SSD
2TB Seagate ST2000DM001
1TB Seagate ST1000DM003
PSU
Corsair HX 650
Case
HAF 932 advanced
Cooling
Corsair H100i liquid cooler
Keyboard
Logitech Wireless
Mouse
Logitech Wireless
Internet Speed
OptusNet NBN 100/40
Antivirus
Malwarebytes
Browser
Firefox 30
Other Info
Router: Sagemcom F@st 3846 Crippled by Optus.
That's where spilled water comes in handy.

Or a glass of water and a trip hazard comes in handy.
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
Back
Top