<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Surf Jacking Secure Cookies</title>
	<atom:link href="http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/feed/" rel="self" type="application/rss+xml" />
	<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=surf-jacking-secure-cookies</link>
	<description>Thoughts on Security in an Uncivilized World…</description>
	<lastBuildDate>Mon, 16 Jan 2012 04:36:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Matt</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-844</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Mon, 09 Nov 2009 16:48:12 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-844</guid>
		<description>A cookie with both the secure flag and the httponly option will resist this attack. Browser won&#039;t send cookie in header and won&#039;t allow JS to access it.</description>
		<content:encoded><![CDATA[<p>A cookie with both the secure flag and the httponly option will resist this attack. Browser won&#8217;t send cookie in header and won&#8217;t allow JS to access it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: L’uomo nel mezzo tutto vede e tutto può - Appunti Digitali</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-747</link>
		<dc:creator>L’uomo nel mezzo tutto vede e tutto può - Appunti Digitali</dc:creator>
		<pubDate>Thu, 12 Mar 2009 17:08:40 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-747</guid>
		<description>[...] in attesa che un utente sprovveduto si colleghi ad un sito non protetto da SSL (benché esistano attacchi ben noti anche per siti protetti con SSL!) e fornisca le sue credenziali in chiaro come token [...]</description>
		<content:encoded><![CDATA[<p>[...] in attesa che un utente sprovveduto si colleghi ad un sito non protetto da SSL (benché esistano attacchi ben noti anche per siti protetti con SSL!) e fornisca le sue credenziali in chiaro come token [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xssniper</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-741</link>
		<dc:creator>xssniper</dc:creator>
		<pubDate>Tue, 24 Feb 2009 18:17:31 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-741</guid>
		<description>True... there is a warning in Internet Explorer, however every other browser I tested did NOT have a mixed content or the warning was given AFTER the mixed content was loaded.

But you are right... even with a warning its difficult for a regular user to make an informed decision.</description>
		<content:encoded><![CDATA[<p>True&#8230; there is a warning in Internet Explorer, however every other browser I tested did NOT have a mixed content or the warning was given AFTER the mixed content was loaded.</p>
<p>But you are right&#8230; even with a warning its difficult for a regular user to make an informed decision.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jasper</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-740</link>
		<dc:creator>jasper</dc:creator>
		<pubDate>Tue, 24 Feb 2009 17:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-740</guid>
		<description>My concern is the &quot;warning&quot; that the page is loading secure and insecure items. Most people would click &quot;yes&quot; to this prompt - boom! Pwned!</description>
		<content:encoded><![CDATA[<p>My concern is the &#8220;warning&#8221; that the page is loading secure and insecure items. Most people would click &#8220;yes&#8221; to this prompt &#8211; boom! Pwned!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wheelq</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-679</link>
		<dc:creator>wheelq</dc:creator>
		<pubDate>Sat, 18 Oct 2008 19:58:49 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-679</guid>
		<description>Hi,

can u contact me at my mail please? I&#039;ve made a post on our website but didn&#039;t get an answer, and it&#039;s quite important for me.


thanks</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>can u contact me at my mail please? I&#8217;ve made a post on our website but didn&#8217;t get an answer, and it&#8217;s quite important for me.</p>
<p>thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xssniper</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-657</link>
		<dc:creator>xssniper</dc:creator>
		<pubDate>Wed, 24 Sep 2008 18:45:49 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-657</guid>
		<description>@barbsie and @x-tense:  I completely agree... this is basically a way to &quot;inject&quot; XSS into an SSL site without presenting the user a SSL cert/mixed content warning (on most browsers).  Starbux wi-fi just got a little more dangerous (not that it isn&#039;t dangerous enough) :)

@Andre and @Sandro:  I agree with you both.  I think SECURE cookies are a solid mitigation... but the current state of implementation weakens the protections significantly</description>
		<content:encoded><![CDATA[<p>@barbsie and @x-tense:  I completely agree&#8230; this is basically a way to &#8220;inject&#8221; XSS into an SSL site without presenting the user a SSL cert/mixed content warning (on most browsers).  Starbux wi-fi just got a little more dangerous (not that it isn&#8217;t dangerous enough) <img src='http://xs-sniper.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>@Andre and @Sandro:  I agree with you both.  I think SECURE cookies are a solid mitigation&#8230; but the current state of implementation weakens the protections significantly</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: x-tense</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-656</link>
		<dc:creator>x-tense</dc:creator>
		<pubDate>Wed, 24 Sep 2008 14:46:52 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-656</guid>
		<description>The attack presented is more XSS than surf jacking doesn&#039;t it ?</description>
		<content:encoded><![CDATA[<p>The attack presented is more XSS than surf jacking doesn&#8217;t it ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sandro Gauci</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-655</link>
		<dc:creator>Sandro Gauci</dc:creator>
		<pubDate>Wed, 24 Sep 2008 14:36:59 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-655</guid>
		<description>Yes this sort of thing makes the secure flag useless. An attacker can do virtually anything, from stealing the secure cookie (as you described), to controlling the victim&#039;s browser remotely, to stealing page contents, install a js keystroke logger. 

Referencing js scripts on HTTP from an HTTPS site is such a bad idea. Yet I&#039;m sure that there are a lot of sites that do it.

And I think there&#039;s other issues to consider apart from cookie stealing. For example, most HTTPS connections are actually started from a link on an HTTP site. Are you thinking what I&#039;m thinking? ;-)

Dan went through this in his BH talk.. and probably others did as well. At this point I think that the way that we do &quot;secure HTTP&quot; is so broken..</description>
		<content:encoded><![CDATA[<p>Yes this sort of thing makes the secure flag useless. An attacker can do virtually anything, from stealing the secure cookie (as you described), to controlling the victim&#8217;s browser remotely, to stealing page contents, install a js keystroke logger. </p>
<p>Referencing js scripts on HTTP from an HTTPS site is such a bad idea. Yet I&#8217;m sure that there are a lot of sites that do it.</p>
<p>And I think there&#8217;s other issues to consider apart from cookie stealing. For example, most HTTPS connections are actually started from a link on an HTTP site. Are you thinking what I&#8217;m thinking? <img src='http://xs-sniper.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Dan went through this in his BH talk.. and probably others did as well. At this point I think that the way that we do &#8220;secure HTTP&#8221; is so broken..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: barbsie</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-654</link>
		<dc:creator>barbsie</dc:creator>
		<pubDate>Wed, 24 Sep 2008 14:31:10 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-654</guid>
		<description>Nice. There&#039;s tons of stuff you can do with MitM attacks. It&#039;s IMHO way more efficient to target the client instead of the server with MitM.
What about injecting CSRF and XSS with beef ( http://video.google.com/videoplay?docid=-7578708518522997029&amp;hl=en). Collecting hits, clickfraud etc...</description>
		<content:encoded><![CDATA[<p>Nice. There&#8217;s tons of stuff you can do with MitM attacks. It&#8217;s IMHO way more efficient to target the client instead of the server with MitM.<br />
What about injecting CSRF and XSS with beef ( <a href="http://video.google.com/videoplay?docid=-7578708518522997029&#038;hl=en" rel="nofollow">http://video.google.com/videoplay?docid=-7578708518522997029&#038;hl=en</a>). Collecting hits, clickfraud etc&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hugo</title>
		<link>http://xs-sniper.com/blog/2008/09/24/surf-jacking-secure-cookies/comment-page-1/#comment-653</link>
		<dc:creator>Hugo</dc:creator>
		<pubDate>Wed, 24 Sep 2008 12:19:17 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/?p=172#comment-653</guid>
		<description>Your SIDENOTE confuses me. If you say, that document.cookie is not accessable for SECURE cookies, how can you steal it?

Perhaps you could rephrase that SIDENOTE to not confuse :)</description>
		<content:encoded><![CDATA[<p>Your SIDENOTE confuses me. If you say, that document.cookie is not accessable for SECURE cookies, how can you steal it?</p>
<p>Perhaps you could rephrase that SIDENOTE to not confuse <img src='http://xs-sniper.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced

Served from: xs-sniper.com @ 2012-02-04 04:23:34 -->
