LinkedIn's Cookies Are Crumbling
25 May, 2011, 1:30 pm IST | by
Padmini Harchandrai
|
|
LinkedIn user accounts are vulnerable to hacking because of the way the social networking site handles its cookies. The warning was made by Rishi Narang, a consultant at Hackers Locked, a security firm. LinkedIn, not unlike many other sites uses cookies that are stored on users' browers which facilitate log-ins without re-inputing login information, however Narang points out that the way LinkedIn handles these cookies isn't the best.
Narang says in particular there are two cookie-related vulnerabilities. The first is from LinkedIn's SSL cookies which don't use a secure SSL flag, which means that session credentials are seen in plaintext. A man-in-the-middle attack is highly possible in this scenario which could be launched by a third party website by remotely redirecting a user to the HTTPS log-in page for LinkedIn, and watching the relevant credentials being passed back and forth. All LinkedIn needs to do to fix this is use the secure flag on any cookies that are used with an HTTPS page, such as the log-in page.
The other vulnerability is that LinkedIn has set its cookies to not expire for a whole year and doesn't cancel cookies once a user logs out. With cookies in hand, a violater can then authenticate as another user. LinkedIn's said it's working on related improvements but for now, users should try to access LinkedIn over secured networks. |
Tags: Social Networking , LinkedIn , Security , Privacy , Cookies , SSL , Internet , Web Services
Under-13 joining limit on Facebook to go
Microsoft redesigns Bing, plays up Facebook link
Alternatives to Youtube catch on with mobile crowd
Have a break from social media have a KitKat... app
Kuwait to regulate social networking sites
Facebook launches patent counterattack against Yahoo
The latest "should they-shouldn't they" event with Facebook is the lift of the minimu...
Leaked Images, Availability, Pricing,
Specs, Pre-order
YouTube is the most preferred and undoubtedly the most popular video...
Social Gifting: The next hot trend?
Social networks have knitted the world too close, and everything one does
10 must-have Google Chrome extensions
Despite Microsoft’s IE gaining its market share and numerous Mozilla...

Asus Eee Pad Transformer Prime TF201 Review
Larry Browne
Mon May 28, 01:36:07
Samsung blocks S-Voice feature on non-Galaxy S III devices
Moud Hanad Anaas
Mon May 28, 00:52:13
Nokia 808 PureView to launch in India this month
Bhagat Dheeraj
Mon May 28, 00:03:09
Sony to roll-out ICS update next week,...
BlackBerry Curve 9320 announced in India...
Microsoft VP talks about Ballmer's...
Cisco won't invest in their Android...

















Mixx
Facebook
Twitter
Digg
delicious
reddit
MySpace
StumbleUpon
LinkedIn































































_011517074205_160x90.jpg)















