{"id":1059,"date":"2018-04-23T10:39:47","date_gmt":"2018-04-23T09:39:47","guid":{"rendered":"http:\/\/www.floyd.ch\/?p=1059"},"modified":"2019-07-19T09:05:22","modified_gmt":"2019-07-19T08:05:22","slug":"schubser-and-his-cookie-dealing-friend","status":"publish","type":"post","link":"https:\/\/www.floyd.ch\/?p=1059","title":{"rendered":"Schubser and his cookie dealing friend"},"content":{"rendered":"<p>I actually forgot to post this in February, so I&#8217;m a little late but the topic is as current as it was back then. One week in February my colleague, Jan Girlich and me took some time to review our tools and make three of them available on github.<\/p>\n<p>Jan wrote a Proof of Concept (PoC) Android app that allows exploiting Java object deserialization vulnerabilities in Android and named this project <a href=\"https:\/\/github.com\/modzero\/modjoda\">modjoda<\/a> (Modzero Java Object Deserialization on Android). To test the issue, he also wrote a vulnerable demo application to try the exploit.<\/p>\n<p>I wrote <a href=\"https:\/\/github.com\/modzero\/mod0schubser\">mod0schubser<\/a>, which provides a simple TCP- and TLS-level Man-In-The-Middle (MITM) proxy for people with python experience. It can be used when all the other proxy tools seem to be too complicated and you just want to do some modifications of the traffic in Python. Additionally, I wrote the <a href=\"https:\/\/github.com\/modzero\/mod0cookiedealer\">mod0cookiedealer<\/a> tool, a tool to demonstrate the impact of missing HTTP cookie flags (secure and HTTPonly). If you remember <a href=\"https:\/\/en.wikipedia.org\/wiki\/Firesheep\">Firesheep<\/a>, mod0cookiedealer is a modern implementation of Firesheep as a browser web-extension.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I actually forgot to post this in February, so I&#8217;m a little late but the topic is as current as it was back then. One week in February my colleague, Jan Girlich and me took some time to review our &hellip; <a href=\"https:\/\/www.floyd.ch\/?p=1059\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[158,199,198,80,197,195,196,194,20],"class_list":["post-1059","post","type-post","status-publish","format-standard","hentry","category-coding","tag-android","tag-deserialisation","tag-firesheep","tag-java","tag-mitm","tag-mod0cookiedealer","tag-mod0schubser","tag-modjoda","tag-python"],"_links":{"self":[{"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/posts\/1059","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1059"}],"version-history":[{"count":3,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/posts\/1059\/revisions"}],"predecessor-version":[{"id":1139,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/posts\/1059\/revisions\/1139"}],"wp:attachment":[{"href":"https:\/\/www.floyd.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1059"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1059"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}