'Surf Jacking' Threatens Secure Browser Sessions
Researchers at Enigma Security this week published a proof of concept that shows how an attacker might hijack browser sessions secured by the popular HTTPS encryption scheme.
HTTPS is used by many banks, e-commerce sites, and other businesses to provide a secure link between a browser and a Web server. But in a paper published Sunday, Enable Security's Sandro Gauci outlined a way that hackers might hijack HTTPS links and defeat the encryption.
In a nutshell, the proof of concept describes a way to use the "301 Moved Permanently" redirection message to fool browsers that are seeking HTTPS sessions. Rather than breaking the encryption, surf jacking essentially takes advantage of the fact that many HTTPS servers and browsers do not make use of the "secure" flag in the browser cookie.
116 views
Post new comment