Home of ABS Computer Technoloogy, Linux and Security Consultants Network Security solutions from our security experts Security solutions for Internet and Network technologies Some of our services for Linux, security, and hosting Contact us





Click here to register.



Bookmark and Share

 

Best of Pittsburgh Award for Systems Engineering Consulting

 

A Better Bureau Approved Company

We are proud to be a Better Business Bureau Accredited Business.

When you look to secure your business, start with an Accredited Business for your security needs.

 

Accept Credit Cards Online

 


Cookie Monster, this one's not from Sesame Street

User: Admin
Date: 9/11/2008 6:47 am
Views: 669
Rating: 1    Rate [
|
]

This post describes the core logic of CookieMonster in more precise terms than the previous overview post. The hope is to drive home exactly how the tool functions, and to underscore that source code counts as speech in this capacity (and in general). In addition, the README that illustrates how the tool is used, and a README describing a "Quick Start" Live CD method for Mac and Windows users who do not have Linux installs are now available. Finally, an example configuration file for the tool is now posted as well. These should hopefully give a clearer picture of how the tool works and how it can be used.

The most crucial aspect of this sort of attack that most people seem to miss is its ability to cull arbitrary cookies for a list of insecure domains from every client IP on a network even when the user is not using those sites at the time. The second most crucial aspect is how the tool is still able to compromise arbitrary insecure SSL sites in the common case without the need to provide such a target list.

More information available here.

PreviousBackNext
 

Contact Us - Home - Site Map

© 2005-2010 ABS Computer Technology, Inc. - All Rights Reserved
SpamZapper® is the registered trademark of ABS Computer Technology, Inc.

Site Design - Marc Dorsett Graphic Artist