ºÝºÝߣ

ºÝºÝߣShare a Scribd company logo
Session hijacking
Adam Ka?par, kas381
adam.kaspar@gmail.com

27.12.201
3
Session
? Slou?¨ª k identifikaci mezi jednotliv?mi
requesty
? P?enos p?es HTTP protokol
? Zp?sob p?enosu:
?
?
?

Parametr v URL
Skryt¨¦ formul¨¢?ov¨¦ pole
Cookies

? SESSIONID=KBY1T2ywyKtQULVDJfiU1ChG;
Session fixation
? Session se ulo?¨ª p?¨ªmo do URL
? Zasl¨¢n¨ª URL ob¨§ti
? Po p?ihl¨¢?en¨ª ob¨§ti se pou?ije session z
URL
? Str¨¢nky mus¨ª podporovat znovupou?it¨ª
vyexpirovan¨¦ session
? Slu?by:
Session fixation
Session sidejacking
? Uko?ist¨§n¨ª platn¨¦ session cookie
? Lze vyu?¨ªt k neautorizovan¨¦mu p?¨ªstupu k
webov?m slu?b¨¢m, soc. s¨ªt¨ªm atd.
? Session lze zachytit pomoc¨ª packet
sniffingu mezi klientem a serverem
(Wireshark)
Session sidejacking
? Funguje pouze pro nezabezpe?en¨¢
spojen¨ª a s¨ªt¨§
? Web sites pou?¨ªvaj¨ª SSL spojen¨ª pouze
pro autentizaci ¨C n¨¢ro?n¨¦ na v?kon
? Slu?by:
? Prost?ed¨ª:V?B tuonet-simple, free hotspoty
Facebook sidejacking
Facebook sidejacking
? Session v cookie s n¨¢zvem datr
? P?ekop¨ªrovat do hlavi?ky nov¨¦ho
po?adavku
? Session aktivn¨ª a? do odhl¨¢?en¨ª u?ivatele
? http://www.youtube.com/watch?v=1Gyz0_bSioI&
feature=youtu.be
Facebook sidejacking
? Povolit promiskuitn¨ª re?im na s¨ª?ov¨¦ kart¨§
? Automatizovan¨¦ n¨¢stroje jako firesheep
? Ochrana proti sidejackingu:
? p?ipojov¨¢n¨ª do zabezpe?en?ch a d?v¨§ryhodn?ch s¨ªt¨ª
? zapnout podporu SSL protokolu (nutn¨¢ podpora serveru)
D¨§kuji za pozornost.
Ad

Recommended

Dynamicke scannery webovych aplikaci v cloudu
Dynamicke scannery webovych aplikaci v cloudu
Jan Horal¨ªk
?
Easycure
Easycure
Suhani Chandra G
?
Ó³»­¼à¶½¡¢Ó³Ïñ×÷¼Ò¤¬Öª¤Ã¤Æ¤ª¤¯¤Ù¤­¡¢¥Õ¥¡¥ó¤òކ¤­Þz¤ó¤À×÷Æ·×÷¤ê¤Î·½·¨
Ó³»­¼à¶½¡¢Ó³Ïñ×÷¼Ò¤¬Öª¤Ã¤Æ¤ª¤¯¤Ù¤­¡¢¥Õ¥¡¥ó¤òކ¤­Þz¤ó¤À×÷Æ·×÷¤ê¤Î·½·¨
schoowebcampus
?
ÊÀ½çÒ»Öܤϣ°ƒÒ¤ÇÐФ±£¡¥Ô©`¥¹¥Ü©`¥È¥¹¥¿¥Ã¥Õ¤¬½Ì¤¨¤ë¡¸¤³¤ì¤«¤é¡¹¤Î¥°¥í©`¥Ð¥ëÁ¦
ÊÀ½çÒ»Öܤϣ°ƒÒ¤ÇÐФ±£¡¥Ô©`¥¹¥Ü©`¥È¥¹¥¿¥Ã¥Õ¤¬½Ì¤¨¤ë¡¸¤³¤ì¤«¤é¡¹¤Î¥°¥í©`¥Ð¥ëÁ¦
schoowebcampus
?
¿àÊÖÒâʶ¤ò¿Ë·þ£¡ÊýµÄ¥»¥ó¥¹ÏòÉÏÈëÃŽ²×ù£¨µÚ¥Ë»Ø£º·ÖÎöÁ¦±à£©
¿àÊÖÒâʶ¤ò¿Ë·þ£¡ÊýµÄ¥»¥ó¥¹ÏòÉÏÈëÃŽ²×ù£¨µÚ¥Ë»Ø£º·ÖÎöÁ¦±à£©
schoowebcampus
?
Benefits of using IMPL
Benefits of using IMPL
Alkis Vazacopoulos
?
ADF Software Factory - Software aus der Werkstatt
enpit GmbH & Co. KG
?
Higher Purpose and Stakeholder Orientation
Higher Purpose and Stakeholder Orientation
PollenStrategy
?
Ó¢Óï¤Çµç»°¤¹¤ë¼Ê¤Î¥·¥Á¥å¥¨©`¥·¥ç¥ó±ðÑÝϰ£¨×îµÍÏޤΥѥ¿©`¥ó±à£©¡¡ÏÈÉú£ºÐ¡ÁÖ¡¡¤¢¤Ä¤·
Ó¢Óï¤Çµç»°¤¹¤ë¼Ê¤Î¥·¥Á¥å¥¨©`¥·¥ç¥ó±ðÑÝϰ£¨×îµÍÏޤΥѥ¿©`¥ó±à£©¡¡ÏÈÉú£ºÐ¡ÁÖ¡¡¤¢¤Ä¤·
schoowebcampus
?
A k?zoktat¨¢sr¨®l sz¨®l¨® 1993
A k?zoktat¨¢sr¨®l sz¨®l¨® 1993
Drahos Andrea
?
NIRI Annual Conference - 2014 Program Book
NIRI Annual Conference - 2014 Program Book
IR Smartt Inc.
?
Embrace The Evolution
Embrace The Evolution
Christopher Kappes
?
2012 SEO For Press Releases
2012 SEO For Press Releases
IR Smartt Inc.
?
Poverty - G2
Poverty - G2
Bernard Sng
?
Prezentare Your Promo Innovaty
Prezentare Your Promo Innovaty
Andreea Vladau
?
Alat indera
Alat indera
Muhammad Noval
?
Catalunya n? 178 Gener 2016
Catalunya n? 178 Gener 2016
Revista Catalunya
?
ÊÀ¤ÎÖФò‰ä¤¨¤ëÉ«¤ó¤ÊÃæ°×¤¤Èˤ¬³Ö¤Áʱ¼ä500Ãë¤Ç¥Á¥é¥ß¥»¤·¤Þ¤¹£¡°ä±ô¾±±è¡¸¥Á¥é¥ß¥»²Ô¾±²µ³ó³Ù¡¹±¹´Ç±ô.2
ÊÀ¤ÎÖФò‰ä¤¨¤ëÉ«¤ó¤ÊÃæ°×¤¤Èˤ¬³Ö¤Áʱ¼ä500Ãë¤Ç¥Á¥é¥ß¥»¤·¤Þ¤¹£¡°ä±ô¾±±è¡¸¥Á¥é¥ß¥»²Ô¾±²µ³ó³Ù¡¹±¹´Ç±ô.2
schoowebcampus
?
Basisbedrijfsmodel Terreinbeheer
Basisbedrijfsmodel Terreinbeheer
Frank Steeneken
?

More Related Content

Viewers also liked (11)

Ó¢Óï¤Çµç»°¤¹¤ë¼Ê¤Î¥·¥Á¥å¥¨©`¥·¥ç¥ó±ðÑÝϰ£¨×îµÍÏޤΥѥ¿©`¥ó±à£©¡¡ÏÈÉú£ºÐ¡ÁÖ¡¡¤¢¤Ä¤·
Ó¢Óï¤Çµç»°¤¹¤ë¼Ê¤Î¥·¥Á¥å¥¨©`¥·¥ç¥ó±ðÑÝϰ£¨×îµÍÏޤΥѥ¿©`¥ó±à£©¡¡ÏÈÉú£ºÐ¡ÁÖ¡¡¤¢¤Ä¤·
schoowebcampus
?
A k?zoktat¨¢sr¨®l sz¨®l¨® 1993
A k?zoktat¨¢sr¨®l sz¨®l¨® 1993
Drahos Andrea
?
NIRI Annual Conference - 2014 Program Book
NIRI Annual Conference - 2014 Program Book
IR Smartt Inc.
?
Embrace The Evolution
Embrace The Evolution
Christopher Kappes
?
2012 SEO For Press Releases
2012 SEO For Press Releases
IR Smartt Inc.
?
Poverty - G2
Poverty - G2
Bernard Sng
?
Prezentare Your Promo Innovaty
Prezentare Your Promo Innovaty
Andreea Vladau
?
Alat indera
Alat indera
Muhammad Noval
?
Catalunya n? 178 Gener 2016
Catalunya n? 178 Gener 2016
Revista Catalunya
?
ÊÀ¤ÎÖФò‰ä¤¨¤ëÉ«¤ó¤ÊÃæ°×¤¤Èˤ¬³Ö¤Áʱ¼ä500Ãë¤Ç¥Á¥é¥ß¥»¤·¤Þ¤¹£¡°ä±ô¾±±è¡¸¥Á¥é¥ß¥»²Ô¾±²µ³ó³Ù¡¹±¹´Ç±ô.2
ÊÀ¤ÎÖФò‰ä¤¨¤ëÉ«¤ó¤ÊÃæ°×¤¤Èˤ¬³Ö¤Áʱ¼ä500Ãë¤Ç¥Á¥é¥ß¥»¤·¤Þ¤¹£¡°ä±ô¾±±è¡¸¥Á¥é¥ß¥»²Ô¾±²µ³ó³Ù¡¹±¹´Ç±ô.2
schoowebcampus
?
Basisbedrijfsmodel Terreinbeheer
Basisbedrijfsmodel Terreinbeheer
Frank Steeneken
?
Ó¢Óï¤Çµç»°¤¹¤ë¼Ê¤Î¥·¥Á¥å¥¨©`¥·¥ç¥ó±ðÑÝϰ£¨×îµÍÏޤΥѥ¿©`¥ó±à£©¡¡ÏÈÉú£ºÐ¡ÁÖ¡¡¤¢¤Ä¤·
Ó¢Óï¤Çµç»°¤¹¤ë¼Ê¤Î¥·¥Á¥å¥¨©`¥·¥ç¥ó±ðÑÝϰ£¨×îµÍÏޤΥѥ¿©`¥ó±à£©¡¡ÏÈÉú£ºÐ¡ÁÖ¡¡¤¢¤Ä¤·
schoowebcampus
?
A k?zoktat¨¢sr¨®l sz¨®l¨® 1993
A k?zoktat¨¢sr¨®l sz¨®l¨® 1993
Drahos Andrea
?
NIRI Annual Conference - 2014 Program Book
NIRI Annual Conference - 2014 Program Book
IR Smartt Inc.
?
2012 SEO For Press Releases
2012 SEO For Press Releases
IR Smartt Inc.
?
Prezentare Your Promo Innovaty
Prezentare Your Promo Innovaty
Andreea Vladau
?
ÊÀ¤ÎÖФò‰ä¤¨¤ëÉ«¤ó¤ÊÃæ°×¤¤Èˤ¬³Ö¤Áʱ¼ä500Ãë¤Ç¥Á¥é¥ß¥»¤·¤Þ¤¹£¡°ä±ô¾±±è¡¸¥Á¥é¥ß¥»²Ô¾±²µ³ó³Ù¡¹±¹´Ç±ô.2
ÊÀ¤ÎÖФò‰ä¤¨¤ëÉ«¤ó¤ÊÃæ°×¤¤Èˤ¬³Ö¤Áʱ¼ä500Ãë¤Ç¥Á¥é¥ß¥»¤·¤Þ¤¹£¡°ä±ô¾±±è¡¸¥Á¥é¥ß¥»²Ô¾±²µ³ó³Ù¡¹±¹´Ç±ô.2
schoowebcampus
?
Basisbedrijfsmodel Terreinbeheer
Basisbedrijfsmodel Terreinbeheer
Frank Steeneken
?

Session hijacking

  • 1. Session hijacking Adam Ka?par, kas381 adam.kaspar@gmail.com 27.12.201 3
  • 2. Session ? Slou?¨ª k identifikaci mezi jednotliv?mi requesty ? P?enos p?es HTTP protokol ? Zp?sob p?enosu: ? ? ? Parametr v URL Skryt¨¦ formul¨¢?ov¨¦ pole Cookies ? SESSIONID=KBY1T2ywyKtQULVDJfiU1ChG;
  • 3. Session fixation ? Session se ulo?¨ª p?¨ªmo do URL ? Zasl¨¢n¨ª URL ob¨§ti ? Po p?ihl¨¢?en¨ª ob¨§ti se pou?ije session z URL ? Str¨¢nky mus¨ª podporovat znovupou?it¨ª vyexpirovan¨¦ session ? Slu?by:
  • 5. Session sidejacking ? Uko?ist¨§n¨ª platn¨¦ session cookie ? Lze vyu?¨ªt k neautorizovan¨¦mu p?¨ªstupu k webov?m slu?b¨¢m, soc. s¨ªt¨ªm atd. ? Session lze zachytit pomoc¨ª packet sniffingu mezi klientem a serverem (Wireshark)
  • 6. Session sidejacking ? Funguje pouze pro nezabezpe?en¨¢ spojen¨ª a s¨ªt¨§ ? Web sites pou?¨ªvaj¨ª SSL spojen¨ª pouze pro autentizaci ¨C n¨¢ro?n¨¦ na v?kon ? Slu?by: ? Prost?ed¨ª:V?B tuonet-simple, free hotspoty
  • 8. Facebook sidejacking ? Session v cookie s n¨¢zvem datr ? P?ekop¨ªrovat do hlavi?ky nov¨¦ho po?adavku ? Session aktivn¨ª a? do odhl¨¢?en¨ª u?ivatele ? http://www.youtube.com/watch?v=1Gyz0_bSioI& feature=youtu.be
  • 9. Facebook sidejacking ? Povolit promiskuitn¨ª re?im na s¨ª?ov¨¦ kart¨§ ? Automatizovan¨¦ n¨¢stroje jako firesheep ? Ochrana proti sidejackingu: ? p?ipojov¨¢n¨ª do zabezpe?en?ch a d?v¨§ryhodn?ch s¨ªt¨ª ? zapnout podporu SSL protokolu (nutn¨¢ podpora serveru)