This is a simple demonstration of how to perform a Session Hijacking attack on the Facebook application for the iPhone. The attack uses the persistent cookie that is stored so that user's do not have to authenticate each time they launch the application.
Article describing this vulnerability in more detail:
Security Focus Ref:
http://www.securityfocus.com/archive/1/509514/30/0/threaded
Link to this comment:
All Comments (0)