sniffing http session cookies and using it for session hijack

viktik

Level 25
Thread author
Verified
Well-known
Sep 17, 2013
1,492
This one is very simple to do.

Anyone using http session can be easily hijacked

  • Just sniff the http session of a website using wireshark
  • Note the captured Cookie
HTTP COOKIE HIJACK  SCREENSHOT_17-05-2015_16-22-11.jpg


  • open a web browser
  • Add the name and value of captured cookie. save it.
  • open the website . Now you are logged into someone else account.


HTTP COOKIE HIJACK  SCREENSHOT_17-05-2015_16-22-46.jpg


You can do anything on that website , which is allowed to be done without asking for username and password. All this just by using the sniffed cookies.


Anyone can sniff on data traveling through hub, switches, router that you are using to connect to internet. They can easily hijack your http sessions.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top