178
2 Computer Viruses, Malicious Logic, and Spyware
(1) Cross-site scripting. This is the simplest and most popular way of stealing
cookies. It is based on introduction of a small Trojan script transferring cookies
accessible to the site to the intruder into a legitimate web page. The feature of
cross-site scripting is the fact that it helps steal session cookies;
(2) Exploiting browser vulnerabilities;
(3) Injection of the user PC with the Trojan, which will analyze information
contained in cookies and transfer it to its creators. Alternatively, a Trojan
program can not only analyze cookies, but also modify them. Creating such
program is quite simple, as Internet Explorer and Mozilla Firefox store cookies
in an open form;
(4) Using computer in public access location (libraries, Internet cafes, etc.). Many
users don’t think about the necessity to delete operation logs and cookies after
completion of work;
(5) Interception of cookies using network traffic analysis means;
(6) Registration of cookie data in the proxy server protocol. Depending on the
settings, the proxy server can record not only the full URL, but also the HTTP
request and response headers.
Several main hazard types are associated with cookies:
(1) Confidential information leakage. Possible if the intruder acquires data stored
in cookies by any means;
(2) Unauthorized access of the intruder to certain web services under the user’s
name. First of all, it is associated with receiving the session identifier, user
name, and password stored in cookies or their equivalent;
(3) Analysis of the nods visited by the user in recent time. In this case cookies,
along with browser logs and caches of pages provide a fairly complete picture
of the sites visited by the user. Such analysis is usually performed by specialists of secret services or security service as one of the elements of computer
examination.
Let us briefly consider the methods of finding cookies that contain confidential
information.
Online analysis of cookies is usually performed with the help of the antivirus
utility AVZ, which contains the tool for finding given text fragments in the content of
the cookies saved by Internet Explorer and Mozilla Firefox. Search system window
is called from the “Service/Find Cookies” menu. A feature of the Cookies Search
system is that it can run the search using several text patterns simultaneously, separated with a space or semicolon. The search factors in the fact that cookies can contain
data in Base64, UUE, URL encoding, or quoted-printable (QP) formats. Analyzed
formats can be selected on the “Settings” tab; by default, search is performed in all
formats (Fig. 2.29).
To run analysis, in the “Pattern” field, type fragments of the user’s e-mail addresses
used for signing into websites, passwords, fragments of credit card numbers, or other
details that had been entered in web forms and the leaking of which poses a threat
to the user. When entering search patterns, bear in mind that the application actually
Précédent

- 199/839

Suivant