{"id":2412,"date":"2008-09-12T00:00:00","date_gmt":"2008-09-12T00:00:00","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/2008\/09\/12\/cookiemonster-can-steal-https-cookies\/"},"modified":"2021-12-30T11:41:18","modified_gmt":"2021-12-30T11:41:18","slug":"cookiemonster-can-steal-https-cookies","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/2008\/09\/12\/cookiemonster-can-steal-https-cookies\/","title":{"rendered":"CookieMonster Can Steal HTTPS Cookies"},"content":{"rendered":"<p>The Python-based tool actively gathers insecure SSL information and records that as well as normal HTTP cookies to Firefox-compatible cookie files.  A so-called CookieMonster attack is coming, and if you use Web-based services that involve login credentials, such as Web e-mail or online banking, you may want to turn your fear and paranoia dial to 11, one researcher warns.  &#8220;CookieMonster is a Python-based tool that actively gathers insecure HTTPS cookies, and records these as well as normal http cookies to Firefox compatible cookie files,&#8221; explains Mike Perry, the security researcher who created the software, in a documentation file.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sadly, it turns out that many Web sites do not properly set the &#8220;Encrypted Sessions Only&#8221; property of their cookies.<\/p>\n<p>Because HTTPS cookies are full of tasty authentication information, they can be used to access online banking accounts, Webmail accounts, and the like.<\/p>\n<p>Perry proposes the following test to see whether sites you use are vulnerable: &#8220;To check your sites under Firefox, go to the Privacy tab in the Preferences window, and click on &#8216;Show Cookies.&#8217;  For a given site, inspect the individual cookies for the top level name of the site, and any subdomain names, and if any have &#8216;Send For: Encrypted connections only,&#8217; delete them.<\/p>\n<p>Having tried these steps with two &#8220;Encrypted connections only&#8221; Google (NSDQ: GOOG) cookies, Google appears to be vulnerable to a CookieMonster attack.  A Google spokesperson confirmed this to be the case and said the company&#8217;s engineers are working with Perry to eliminate the vulnerability.<\/p>\n<p>http:\/\/www.informationweek.com\/news\/security\/vulnerabilities\/showArticle.jhtml;jsessionid=2P0R3N2D1VQU4QSNDLPCKH0CJUNN2JVN?articleID=210601197<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"class_list":["post-2412","post","type-post","status-publish","format-standard","hentry","category-warnings"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/posts\/2412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=2412"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/posts\/2412\/revisions"}],"predecessor-version":[{"id":4899,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/posts\/2412\/revisions\/4899"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=2412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=2412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=2412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}