We will ﬁrst describe the components that make up this vulnerability for those who do not have in-depth knowledge of HTTP and HTTPS. If you’re familiar with the HTTP protocol, feel free to skip to the section “underlying protocols”.
EnableSecurity is releasing a tool called surfjack.py which demonstrates the ideas described in this paper. In the section “Proof of Concept” we describe how the tool works and the various options that it supports.
Finally we will describe a simple solution that was successfully applied to two Banks found vulnerable. We shall also discuss why this solution might not be so straightforward to implement in large Single Sign-On services such as Google’s network.
Download the paper in PDF format here.
A video demo of Surf Jacking Gmail can be viewed here.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.