Remember to delete (or eat) cookies regularly !!!

xReminisce

Elite Member
Joined
Dec 29, 2012
Messages
7,329
Reaction score
36,654

Cybercriminals Are Stealing Cookies to Bypass Multifactor Authentication​

https://www.fbi.gov/contact-us/fiel...-cookies-to-bypass-multifactor-authentication
The FBI Atlanta Division is warning the public that cybercriminals are gaining access to email accounts by stealing cookies from a victim’s computer. A “cookie” is a small piece of data that a website sends to your computer, allowing the website to remember information about your session, such as login details, preferences, or items in your shopping cart. “Remember-Me cookies” are tied specifically to a user’s login and often last for 30 days before expiring. This type of cookie helps a user login without having to keep putting in their username, password, or their multifactor authentication (MFA). Typically, this type of cookie is generated when a user clicks the “Remember this device” checkbox when logging in to a website:

If a cybercriminal obtains the Remember-Me cookie from a user’s recent login to their web email, they can use that cookie to sign-in as the user without needing their username, password, or multifactor authentication (MFA). For these reasons, cybercriminals are increasingly focused on stealing Remember-Me cookies and using them as their preferred way of accessing a victim’s email. Victims unknowingly provide their cookies to cybercriminals when they visit suspicious websites or click on phishing links that download malicious software onto their computer
 
curios, how does that work
Well, first off, this isn't an hacking forum
second, as if the FBI or any agency would tell us how they are finding these things or how it works :(
but if i was to guess
1 of 2 ways
1. website gets hacked/hosting providers sell data
2. end-user is infected
 
I wonder why are you visiting FBI's website? Hmmm.

Jokes apart, this is concerning if true.

Thanks for keeping us posted @xReminisce
i like to be well-informed :)

either way, rule of thumb is, you should never log into any banking or important details under remember me anyways and never save cookies for them.
standalone emails clients are preferred or use a PVA on a browser dedicated to just emails
 
I mean, if regular browsers would have such a feature, it would be quite a big vulnerability.

It was early 2008'-ish if I recall correctly when I did such attacks and was able to harvest cookies by getting people visit my domains

nowadays if you don't download anything, I'm not sure of how it would be possible to get access to cookies in such way, thats why I did ask, as I think this statement is wrong

it would make more sense for installing malicious browser extensions

other than that - yeah, keep your cookies safe, while its quite a challenge to not only obtain them but replicate the system params to be able to read them and load them up for use, its still doable, yeah
 
I mean, if regular browsers would have such a feature, it would be quite a big vulnerability.

It was early 2008'-ish if I recall correctly when I did such attacks and was able to harvest cookies by getting people visit my domains

nowadays if you don't download anything, I'm not sure of how it would be possible to get access to cookies in such way, thats why I did ask, as I think this statement is wrong

it would make more sense for installing malicious browser extensions

other than that - yeah, keep your cookies safe, while its quite a challenge to not only obtain them but replicate the system params to be able to read them and load them up for use, its still doable, yeah
you would be amazed how stupid people are in clicking stupid things
downloading random stuff
and installing "cool" things
I agree as for an avg user who comfortable in tech and isn't stupid, this isn't probably much to worry about
 
curios, how does that work
well i don’t think you can as long they are secure httponly cookies… but what stops you from making ajax calls to third party websites and get authed data? :D

Oh I guess that’s why CORS exists.

but then… do the chatgpt devs know what could happen? There lies the problem. ;)
 
What's that?
food
BAKERY-STYLE-CHOCOLATE-CHIP-COOKIES-9.jpg
 
They are the one who are buying this data from the legit cookies - They are the one who are doing all this haha - JOKES APART but this is a new to me. lol
 
I doubt they get most cookies by the victim downloading a malicious file. But i do wonder what other tactics are used to steal cookies.
 
Back
Top