module

Apple OSX/iOS/Windows Safari Non-HTTPOnly Cookie Theft

Disclosed
Apr 8, 2015
Created
May 30, 2018

Description

A vulnerability exists in versions of OSX, iOS, and Windows Safari released
before April 8, 2015 that allows the non-HTTPOnly cookies of any
domain to be stolen.

Authors

Jouko Pynnonen
joev [email protected]

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/gather/apple_safari_ftp_url_cookie_theft
msf auxiliary(apple_safari_ftp_url_cookie_theft) > show actions
...actions...
msf auxiliary(apple_safari_ftp_url_cookie_theft) > set ACTION < action-name >
msf auxiliary(apple_safari_ftp_url_cookie_theft) > show options
...show and set options...
msf auxiliary(apple_safari_ftp_url_cookie_theft) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.