Return of the Cookie Monster

Summary

This article explores how adversaries can still exploit authenticated browser sessions despite improved cookie protections by using the Chrome DevTools Protocol (CDP). It details methods for performing post-exploitation activities like browser enumeration, cookie theft, and browser takeover within a running Chromium browser.

IFF Assessment

FOE

The article details new techniques adversaries can use to steal authentication cookies and take over browser sessions, which is detrimental to defenders.

Defender Context

Defenders should be aware that traditional session theft methods may be evolving with the use of tools like the Chrome DevTools Protocol. Monitoring for unusual browser activity or the exploitation of authenticated sessions remains crucial.

Read Full Story →