I discovered 2 dangerous Security vulnerabilities at Etisalat.eg - TopicsExpress



          

I discovered 2 dangerous Security vulnerabilities at Etisalat.eg website during Password Recovery Process :D :D 1 - Cookies Not Marked As HttpOnly (an attacker might easily access cookies and hijack the victims session.) 2 - Critical Form Served Over HTTP (If an attacker can carry out a MITM (Man in the middle) attack, attacker may be able to intercept traffic by injecting JavaScript code into this page or changing action of the HTTP code to steal the users password.
Posted on: Sat, 18 Jan 2014 21:41:15 +0000

Trending Topics



Recently Viewed Topics




© 2015