Hackers Think Cookies Are Tasty, Too
blog.tinfoilsecurity.com
Hackers Think Cookies Are Tasty, Too
1–10 of 14 posts
Re: Hackers Think Cookies Are Tasty, Too
#2That said, as far as the server trusting cookie values to do database lookups or whatever, sure, there's a hole there. Most folks will use something like HMAC-signed cookies in those cases, so that an attacker would have to be in possession of a secret key in order to successfully have altered cookie data accepted by the user. But in any case, the data should be treated like any other user-supplied data - untrusted and to be sanitized.
Re: Hackers Think Cookies Are Tasty, Too
#3Of course, cookies are still client-side data and should not be trusted. But XSS is not a problem here. Correct me if I'm wrong.
Re: Hackers Think Cookies Are Tasty, Too
#4Re: Hackers Think Cookies Are Tasty, Too
#5Isn't XSS only a client side danger? For URLs, this is relevant since you can post a malicious link and people can click on it. It's much harder to get someone else's browser to accept a cookie you made for a specific website. Of course, cookies are still client-side data and should not be trusted. But XSS is not a problem here. Correct me if I'm wrong.
Re: Hackers Think Cookies Are Tasty, Too
#6But...in order to properly execute an XSS attack, you have to get your code onto someone else's computer. You can edit your own cookies all day long and accomplish nothing of value. What piece am I missing here? That said, as far as the server trusting cookie values to do database lookups or whatever, sure, there's a hole there. Most folks will use something like HMAC-signed cookies in those cases, so that an attacke…
Re: Hackers Think Cookies Are Tasty, Too
#7But...in order to properly execute an XSS attack, you have to get your code onto someone else's computer. You can edit your own cookies all day long and accomplish nothing of value. What piece am I missing here? That said, as far as the server trusting cookie values to do database lookups or whatever, sure, there's a hole there. Most folks will use something like HMAC-signed cookies in those cases, so that an attacke…
Re: Hackers Think Cookies Are Tasty, Too
#8But...in order to properly execute an XSS attack, you have to get your code onto someone else's computer. You can edit your own cookies all day long and accomplish nothing of value. What piece am I missing here? That said, as far as the server trusting cookie values to do database lookups or whatever, sure, there's a hole there. Most folks will use something like HMAC-signed cookies in those cases, so that an attacke…
Re: Hackers Think Cookies Are Tasty, Too
#9But...in order to properly execute an XSS attack, you have to get your code onto someone else's computer. You can edit your own cookies all day long and accomplish nothing of value. What piece am I missing here? That said, as far as the server trusting cookie values to do database lookups or whatever, sure, there's a hole there. Most folks will use something like HMAC-signed cookies in those cases, so that an attacke…
Yes, I think what the original article is saying is that the cookie could have been altered by a rogue browser extension/virus on a user's computer, which could be then potentially used to import a script from a different origin into the user's page.
Re: Hackers Think Cookies Are Tasty, Too
#10Isn't it a widely adopted practice to encrypt the content of the cookie before setting it? Of course it could still be tampered with, but not as trivially.