LinuxVillage

LinuxVillage welcome => Technical discussions => Discussion démarrée par: ka9yhd le 17 juillet 2013 à 03:55:11

Titre: Office 365, Amazon, Others Vulnerable To Exploit Microsoft Knew About In 2012
Posté par: ka9yhd le 17 juillet 2013 à 03:55:11
Office 365, Amazon, Others Vulnerable To Exploit Microsoft Knew About In 2012

"Ethical hacking professor Sam Bowne recently put a cookie re-use method to test on several major web services, finding that Office 365, Yahoo mail, Twitter, LinkedIn, Amazon, eBay, and WordPress all failed the security test. Both Amazon and eBay can be tied directly to your money via the method of payment you have on record. And, just for kicks, we tried it with Netflix. And it worked. Microsoft has apparently known that accounts can be hijacked since at least 2012 when The Hacker News reported the Hotmail and Outlook cookie-handling vulnerability, so Bowne was curious if Microsoft closed the hole or if stolen cookies could still be re-used. He claims he 'easily reproduced it using Chrome and the Edit This Cookie extension.'"

http://tech.slashdot.org/story/13/07/16/2151232/office-365-amazon-others-vulnerable-to-exploit-microsoft-knew-about-in-2012 (http://tech.slashdot.org/story/13/07/16/2151232/office-365-amazon-others-vulnerable-to-exploit-microsoft-knew-about-in-2012)