Skip to content

Comment on Hypertext Transfer Protocol Version 2parent

Comments

Currently on the front page is an article[1] about Russian malware pen testing for SQL injection. Your attack surface increases dramatically when you have valid session cookies.

A good example of this is reddit, that is not https for logged in users with write ability (and thus PostgreSQL write ability). If you have malware that sniffs public wifi traffic for reddit session cookies, you can easily start to test all those write calls for exploits.

[1] - http://www.nytimes.com/2014/08/06/technology/russian-gang-sa...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.