What Is a Sidejacking Attack?
Uploader Comments (LiveSecurity)
All Comments (26)
-
Thankyou for teaching me this :|
-
sarah is beautiful!
-
Will it work with online flash games? I want to steal people's accounts.
-
so basicly the only way the hacker can get to my g mail then he has to be logged on to my network, hence not possible
-
@ZepplinProgramming The only hard part i that is getting them to accept the fake certificate. Worked on my sister though :)
-
Gotta admit though, for how potentially dangerous this attack can be it is fucking easy
-
Easy to understand.. Cool~! but it make me sad about can not trust world.. Hmm.. Bye..
-
Knew it. Just another whitehat buzzword for an old technique.
Jesus Christ whitehats.
-
While encryption may be a little more secure and would prevent this particular attack, all a malicious user would have to do is fire up Ettercap and do ARP poisoning on their target computer and then generate a fake SSL certificate and if the user accepts they can de-crypt all traffic.
Great video though, 5 stars!
-
holy-terrorist:> *=* hahaha im new sidejacker *=*
Can this also be done against other mail clients such as Yahoo?
steadysnper 4 years ago
Yes, the point is that the attacker can see the victim's login credentials. Any web site the victim logs into can work for the attacker, UNLESS the victim has configured the site to encrypt sessions.
LiveSecurity 4 years ago