Attackers can Bypass MFA by Exploiting Authentication Cookie

Share post:

Multi-factor authentication is an important security measure for users and organizations. However, it is not enough, as attackers can manipulate and bypass it via the cookie authentication available on websites.

According to a recent release from Sophos, “Cookies associated with authentication to web services can be used by attackers in ‘pass the cookie’ attacks, attempting to masquerade as the legitimate user to whom the cookie was originally issued and gain access to web services without a login challenge.”

Attackers steal cookies via malware that sends exact copies of session cookies to the attacker. In addition, multiple stolen credentials now allow the ability to steal cookies.

Like any other malware, users’ computers can be infected with cookie malware. According to Sophos researchers, attackers use paid download services and other non-targeted approaches to collect as many cookies as possible.

Some of the strategies used include storing the malware in large ISOs or ZIP archives when it is advertised on websites, offering it via peer-to-peer networks and distributing it via emails.

Users can protect themselves against this type of attack by enforcing encryption, if possible, strict computer security hygiene and security solutions to detect malware.

The sources for this piece include an article in TechRepublic.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

UK legislation bans weak passwords

Starting Monday, the UK will enforce new laws banning the sale of devices with weak default passwords such...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways