Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

What Is a Sidejacking Attack?

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
27,351
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Oct 23, 2007

Corey Nachreiner, CISSP, demonstrates a relatively simple way for someone sitting near you at a wireless hotspot to steal your credentials for any Web account you log into... then later, log on as you and see your private info. Based on a Black Hat presentation by Robert Graham of Errata Security.

  • likes, 3 dislikes

Link to this comment:

Share to:

Uploader Comments (LiveSecurity)

  • Can this also be done against other mail clients such as Yahoo?

  • Yes, the point is that the attacker can see the victim's login credentials. Any web site the victim logs into can work for the attacker, UNLESS the victim has configured the site to encrypt sessions.

see all

All Comments (26)

Sign In or Sign Up now to post a comment!
  • Thankyou for teaching me this :|

  • sarah is beautiful!

  • Will it work with online flash games? I want to steal people's accounts.

  • so basicly the only way the hacker can get to my g mail then he has to be logged on to my network, hence not possible

  • @ZepplinProgramming The only hard part i that is getting them to accept the fake certificate. Worked on my sister though :)

  • Gotta admit though, for how potentially dangerous this attack can be it is fucking easy

  • Easy to understand.. Cool~! but it make me sad about can not trust world.. Hmm.. Bye..

  • Knew it. Just another whitehat buzzword for an old technique.

    Jesus Christ whitehats.

  • While encryption may be a little more secure and would prevent this particular attack, all a malicious user would have to do is fire up Ettercap and do ARP poisoning on their target computer and then generate a fake SSL certificate and if the user accepts they can de-crypt all traffic.

    Great video though, 5 stars!

  • holy-terrorist:> *=* hahaha im new sidejacker *=*

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more