Italian security researcher Rosario Valotta has discovered a new way for hackers to steal their victims’ online credentials — stealing the session cookies from whatever site a victim is visiting. The stolen cookies can then be used to get victims’ computers to download malware, forge clicks or send messages, according to Valotta’s website. The attack, which Valotta dubbed “cookiejacking,” works on all versions of Internet Explorer across all versions of the Windows operating system, the researcher contends.
Internet Explorer Flaw Lets Hackers Into the Cookie Jar
Posted by: Richard Adhikari May 27, 2011 05:00 AMItalian security researcher Rosario Valotta has discovered a new way for hackers to steal their victims’ online credentials — stealing the session cookies from whatever site a victim is visiting. The stolen cookies can then be used to get victims’ computers to download malware, forge clicks or send messages, according to Valotta’s website. The attack, which Valotta dubbed “cookiejacking,” works on all versions of Internet Explorer across all versions of the Windows operating system, the researcher contends.