New 'Cookiejacking' Threat Hits Internet Explorer
An Italian security researcher has found a new security flaw in Microsoft's Internet Explorer web browser that could allow hackers to steal login information and passwords.
The threat comes in the form of a 'cookiejacking' scheme (related to session hijacking), which allows hackers to review website history and then use that to enter protected domains.
Rosario Valotta recently demonstrated his cookingjacking findings at security conferences in Switzerland and Amsterdam. He acknowledged that exploiting the flaw isn't particularly easy, requiring a hacker to convince an online user to drag and drop an item on their PC in order for the cookie to be extracted and then exploited. (Source: informationweek.com)
Drag and Drop Scheme Fools Facebook Users
If the scheme sounds complex, it really isn't.
Valotta demonstrated to his audience that crafting a malicious Facebook page to require a user to 'drag and drop' is as simple using a Facebook game.
In his example, Valotta made a game that allows a user to drag clothes off the picture of a good-looking woman, which then performed the 'drag and drop' action, thus allowing him access to the user's Facebook credentials (via cookie) in the process.
"I published this game online on Facebook and in less than three days, more than 80 cookies were sent to my server," Valotta said. "And I've only got 150 friends."
Those cookies could then be examined for login and password information. They could then be used to hijack accounts of all sorts, including those associated with financial institutions.
Microsoft: Threat Not "High Risk"
Surprisingly, Microsoft doesn't seem all that bothered by the flaw.
"Given the level of required user interaction, this issue is not one we consider high risk in the way a remote code execution would possibly be to users," said Microsoft spokesman, Jerry Bryant. (Source: cnet.com)
"In order to possibly be impacted, a user must visit a malicious Web site, be convinced to click and drag items around the page and the attacker would need to target a cookie from the Web site that the user was already logged into."
"We encourage all customers to protect themselves against potential issues by avoiding clicking on suspicious links and email, as well as adjusting Internet settings to higher security levels," Bryant added.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.