How can i hack a session if i have the cookie information?

Hi All,
I am in the process of testing an application in my organization for the security vulnerabilities.
I saw a tutorial where an attacker launches an attack and get the cookie details of the victim. Now what step is next the hacker will do to launch a successful attack, this is what i want to know.
Can anyone tell me how can i hack/replicate a session of another user (who is logged in to X application) and i have the cookie details of this logged in user?
Thanks in advance.
-Abhi.

Well i am just a white hat with no intentions of stealing information at all. I am just a beginner in the field of security testing.
Also about abhi, i am not the only abhi there may be a millions of abhi.
I watched a video on XSS injection where i saw that the hacker is able to figure out the session information of the victim. The link is as below:
http://www.virtualforge.de/vmovie/xss_lesson_1/xss_selling_platform_v1.0.html
After watching this video i thought that how a hacker may be able to exploit the session information of some other user. That is why i took the path of posting in forums.
I just needed to know if i am able to find this security vulnerability in one of the applications developed in my organization. Further i would like to report this vulnerability if it existed.
Thanks,
Abhi
(White Hat)
:-)

Similar Messages

  • HT201150 How can I turn off this "feature" and have the power button bring me the shut down / restart / sleep dialog by default again?

    How can I turn off this "feature" and have the power button bring me the shut down / restart / sleep dialog by default again?
    With the position of the power button on the Retina MacBooks, any mistake turns off the screen in the middle of a presentation or any activity using a projector or big screen — a huge waste of time to wake up the display, enter password, have the projector sync back, watch audience disconnecting from what was being discussed, etc.
    This is very annoying, and seems to add to the increasing collection of options Apple decided to make by itself instead of allowing the user to choose.
    Come on Apple guys, I'm using my Mac because I want options and lots of preferences to tweak to my needs.
    If I needed the lobotomized version I'd be using my iPad!
    Any way (official or hack) to change this button back to its proper funcionality?
    Thanks!

    cterra wrote:
    How can I turn off this "feature" and have the power button bring me the shut down / restart / sleep dialog by default again?
    Not what you want, but you can get the shut down / restart / sleep dialog by holding the power button

  • I recently purchase an ipad2.  I also have a mac laptop.  Now, when I facetime call using my iphone to my ipad2 or mac, it states busy.  how can i fix this problem?  I have the same apple id e mail for both ipad2 and mac.  it might be getting confuse now.

    I recently purchase an ipad2.  I also have a mac laptop.  Now, when I facetime call using my iphone to my ipad2 or mac, it states busy.  how can i fix this problem?  I have the same apple id e mail for both ipad2 and mac.  it might be getting confuse now.  I want to be able to face time also using my ipad2 to my laptop especially if one of the members of the family is traveling.  Thanks.

    thanks.  your answer was correct, clearer.  I have another question, maybe you can answer.  I just purchase my ipad2 2 days ago.  yesterday, there was a sound.  today there is no sound.  there is a sound only in movies and you tube and music.  but no sound on all apps and keyboards.  I look it up and seems like ther are few that have this problem.  I called walmart coz I bought it there and they told me that they have not heard that before but if I can't fix it, just return it and exchange it with anew one since I have 14 days to do that.  I tried rebooting it and still won't work.  Should I just restore it?

  • I have an iMac running OS 10.4.11. How can I check to see if I have the Flashback Trojan (and remove it, if I have it)? IMy Safari is also crashing frequently. Any suggestions?

    I have an iMac running OS 10.4.11. How can I check to see if I have the Flashback Trojan (and remove it, if I have it)? IMy Safari is also crashing frequently. Any suggestions?

    Hi Barry, is this an Intel iMac, or a PPC iMac?
    Disable Java in your Browser settings, not JavaScript.
    http://support.apple.com/kb/HT5241?viewlocale=en_US
    http://support.google.com/chrome/bin/answer.py?hl=en-GB&answer=142064
    http://support.mozilla.org/en-US/kb/How%20to%20turn%20off%20Java%20applets
    Flashback - Detect and remove the uprising Mac OS X Trojan...
    http://www.mac-and-i.net/2012/04/flashback-detect-and-remove-uprising.html
    In order to avoid detection, the installer will first look for the presence of some antivirus tools and other utilities that might be present on a power user's system, which according to F-Secure include the following:
    /Library/Little Snitch
    /Developer/Applications/Xcode.app/Contents/MacOS/Xcode
    /Applications/VirusBarrier X6.app
    /Applications/iAntiVirus/iAntiVirus.app
    /Applications/avast!.app
    /Applications/ClamXav.app
    /Applications/HTTPScoop.app
    /Applications/Packet Peeper.app
    If these tools are found, then the malware deletes itself in an attempt to prevent detection by those who have the means and capability to do so. Many malware programs use this behavior, as was seen in others such as the Tsunami malware bot.
    http://reviews.cnet.com/8301-13727_7-57410096-263/how-to-remove-the-flashback-ma lware-from-os-x/
    http://x704.net/bbs/viewtopic.php?f=8&t=5844&p=70660#p70660
    The most current flashback removal instructions are F-Secure's Trojan-Downloader:OSX/Flashback.K.
    https://www.securelist.com/en/blog/208193454/Flashfake_Removal_Tool_and_online_c hecking_site
    More bad news...
    https://www.securelist.com/en/blog/208193467/SabPub_Mac_OS_X_Backdoor_Java_Explo its_Targeted_Attacks_and_Possible_APT_link
    Removal for 10.5...
    http://support.apple.com/kb/DL1534

  • How can I repair my IPod n still have all my information in it or can i get a new one but still with all my information for how much?

    How can I repair my IPod n still have all my information in it or can i get a new one but still with all my information for how much

    - Apple will exchange your iPod for a refurbished one for this price. They do not fix yours. Apple does not transfer any data.
    Apple - iPod Repair price      
    - To backup all your data to computer follow the instructions here. However, do not restore from backup until you have the replacement/repaired iPod.

  • I lost my macbook, how can i find it back? i have the serial number.

    i lost my macbook, how can i find it back? i have the serial number.

    you can not find it unless "find my mac" was enabled and the mac is online.  Also, read this:  http://support.apple.com/kb/ht2526

  • HT5312 Good afternoon, I have forgotten my sequential answers to questions....how can I reset them ? Or else have the answers back again.  I am trying to purchase now and couldn't proceed because of this.  Please assist

    Good afternoon, I have forgotten my sequential answers to questions....how can I reset them ? Or else have the answers back again.  I am trying to purchase now and couldn't proceed because of this.  Please assist

    If you have a rescue email address (which is not the same thing as an alternate email address) set up on your account then steps 1 to 5 on the page that you posted from should work : go to https://appleid.apple.com/ and click 'Manage your Apple ID' on the right-hand side of that page and log into your account. Then click on 'Password and Security' on the left-hand side of that page and on the right-hand side you should see an option to send security question reset info to your rescue email address.
    If you don't have a rescue email address (you won't be able to add one until you can answer 2 of your questions) then you won't get the reset option - you will need to contact iTunes Support or Apple to get the questions reset.
    e.g. you can try contacting iTunes Support : http://www.apple.com/support/itunes/contact/ - click on Contact iTunes Store Support on the right-hand side of the page, then Account Management , and then 'Forgotten Apple ID security questions'
    or try ringing Apple in your country and ask to talk to the Accounts Security Team : http://support.apple.com/kb/HE57
    When they've been reset (and if you don't already have a rescue email address) you can then use the steps half-way down the page that you posted from to add a rescue email address for potential future use.

  • Version 10 doesn't work with a web site I use constantly. How can I download a lower version and have the app appear on my phone?

    Have been using a lower version of firefox on my samsung galaxy phone to access [email protected] for quite some time. Since the upgrade to 10.0, I receive a server error everytime I try to access. Want to download a lower version, but app doesn't appear on my phone. How can I download a lower version and get the app to show up on my phone?

    Mandel is referring to what is called a "User Agent Faker' which tricks the website into thinking it is a different browser or version than it actually is. I sometimes would use this on my iPhone when I wanted to visit the full website of a site I was attempting to go to & it would only take me to the mobile version or state it was only compatible with say Internet Explorer, simply turn it on & select the browser and details you want it to report and it will spoof that browser & you'll be on your way.

  • I cleaned up several albums in iTunes only to have Match wipe all of my changes out.  How can I alter things in iTunes and have the changes stay?

    I signed up for Match but when I added new albums, they failed to appear.  Ultimately I got a message to Sign Out and then Sign In to the Apple Store tab under iTunes.  I then added the computer back to Match.  It went through the process and uploaded the new albums (or matched them) but it also reversed hours of work I had done it editing my library and cleaning up track lists and song titles.
    HOW CAN I edit/maintain my library without Match wiping every change out?????
    And when will the Cover Art issue be solved???

    Match was off.  I made all of the changes and then went through the "Turn on iTunes Match" option.  I now have deleted some tracks, edited the Metadata in CDDA, and then added it back.  This worked fine, but it is not a good solution.
    I just tried making some edits and use the "Update iTunes Match" and that seemed to work.  It looks like the real answer is that Match must be up and operational, then you can make changes and run the Update to incorporate the changes.  However, if Match has a problem then Signing Out and back in to your store account and going through the process of Turning On Match (were you get the questions, "Add this Computer to Match" will overwrite any changes. 
    Since this relies on the stability of iTunes, I won't be making a lot of changes between updates.

  • My ipod was stolen how can i get it back? i have the app find my iphone and i have gone on the mobleme website but it might need to be replaced, could i get any kind of discount? it was a 32GB ipod 4.

    My ipod has been stolen and i may need to get a new one i do not know what to do please help!

    Find my iPhone is relatively useless when it comes to recovering a stolen device. Anyone with a bit of know how can defeat it in a matter of minutes. It's really meant  to help a person find a misplaced device.
    Presume that any and all data and info on that device is compromised, do as Illass says, change any and all passwords to every account or site you accessed on the device and write it off as gone.

  • How can I debug if I don't have the FlexBuilder?

    If my swf file have problems in my client's computer, how can
    I debug?
    As the action script do not allow me to write file and the
    message box cannot reflect the current status of my program.

    You can't. You'll have to connect to your PC.
     Cheers, Tom

  • I would like to be able to keep tabs from last session open but have the cookies follow my exception list. Is this possible?

    For example, I like to keep Gmail (gmail.com) and Pocket (getpocket.com) pinned but when I close Firefox, I want it to remember my pinned tabs but automatically log me out of Gmail but NOT out of Pocket. I can get close to this functionality but Gmail's cookies seem to be tied to browser history. Pocket's are not. If this is not possible, is there a place I can make it a suggestion or is this something to do with Google.
    My privacy settings: nothing checked except 'clear history when firefox closes' -- under that: only 'download history', 'active logins', 'form and search history' and 'cache' are checked.
    Any help would be appreciated.

    Gmail is probably using a secure HTTPS connection.<br />
    If getpocket<i></i>.com is using a normal HTTP connection then you can try this:
    Set the <b>browser.sessionstore.privacy_level</b> pref to 1 (non-HTTPS) on the <b>about:config</b> page to disable saving cookies from secure connection via session restore.
    * http://kb.mozillazine.org/browser.sessionstore.privacy_level

  • How can I update when in theory I have the lattest version of itunes?

    I reinstalled itunes in my computer, and now it won´t let me access my ipad. There is a message that says I need the 11.1 version or later of itunes, but in theory the version I have installed is 11.2. Someone can give me any advise?
    thanks!!

    Rip it up and start again. See the second box in Troubleshooting issues with iTunes for Windows updates.
    tt2

  • How can i configure maps voices? I have the original configuration (standard) and doesn't work

    Hi
    I have an Iphone 5 and doesn't work the voices for navegation (maps app)
    Is there any special configuration requiered
    This feature is very important due i could drive without looking at the phone
    Thanks in advance for your support

    Thanks!!
    Yes, I'm in Chile....sad to hear that this feature is not available everywhere... Those voices should just follow the indications given by maps because maps gives the info about turn left or right so there should be just voices recorded with those standard indications, then this feature would be available everywhere
    But OK...
    Anyways, Thanks for your answer!!!

  • How can I set a Session bean timeout

    Hello !
    How can I set a Session bean to time out eg. 48 hours ?
    Thanks
    Uiloq Slettemark

    For stateful session beans you can use the timeout attribute in the orion-ejb-jar e.g.
    <session-deployment timeout=1800 ..>
    this is specified in seconds and Default Value: 30 (minutes)
    regards
    Debu

Maybe you are looking for