Get a Pentest and security assessment of your IT network.

News

Session Fixation Flaw Keeps Cookies Alive for Major Services after Logout

A new flaw in cookie handling that makes log-ins persistent has been discovered by security researcher Rishi Narang. The new discovery reveals that websites such as Yahoo, LinkedIn and Twitter still keep the cookie/session ID for an authenticated session valid even if they have expired or the user has logged out of his account. Earlier this year, a spam message redirected users to a malicious page where they had their cookies stolen from Yahoo users. If todays report is true, some of the unauthorized account usage reports may still be the result of the cookie harvesting campaign in January.”]

Source: https://www.bitdefender.com/blog/hotforsecurity/session-fixation-flaw-keeps-cookies-alive-for-major-services-after-logout/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin