Menu

Database

Sidejacking

WVE ID: WVE-2008-0003

Type: Exploit

Status: Candidate

Classification:
Cryptographic
Information Disclosure

Description:
Sidejacking is a mechanism to gain unauthorized access to web-based applications that transmit session cookies in plaintext following SSL-based authentication.

Discussion:
Sidejacking is a term described by Errata Security to exploit websites that use HTTPS (SSL) authentication to protect user access credentials, but later revert to HTTP for traffic delivery. Often deployed for performance reasons, the use of HTTP for successive application access typically validates that a client has already been authenticated by issuing a session cookie to the client. For each successive request and response, the session cookie is transmitted in plaintext to validate the legitimate user.
An attacker who observes the cookie transmission can assume the identity of an attacker simply by copying the cookie content to their browser. This has been successfully demonstrated against popular webmail applications including GMail, Yahoo! Mail and Hotmail, where an attacker can observe a legitimate user access mail resources over HTTP and assume their identity. Once the identity of the victim has been assumed, the attacker can access the webmail application as if they had the user's authentication credentials, allowing them to receive, view and send email using the stolen identity.
One mitigation strategy for Sidejacking attacks is to prevent the unauthorized disclosure of information by leveraging encrypted wireless networks.

Credits

References
URL: http://blogs.zdnet.com/Ou/?p=651
URL: http://www.erratasec.com/sidejacking.zip
URL: http://erratasec.blogspot.com/2007/08/sidejacking-with-hamster_05.html

Released: 2007-08-02

Submitter
Joshua Wright (jwright@arubanetworks.com) : Aruba Networks

Submitted: Wed Apr 02 12:22:19 -0700 2008

Candidate Date: Wed Apr 02 12:23:17 -0700 2008


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...