Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. IE Security Flaw Exposes Your Cookies – onmsft.com

IE Security Flaw Exposes Your Cookies – onmsft.com

Ron Ron
May 27, 2011
2 min read

Rosario Valotta, a security researcher from Italy, has discovered a flaw in Internet Explorer that could enable hackers to steal cookies from a user’s PC and then use those cookies to log onto password-protected websites.

As cNet reports, A security researcher from Italy discovered this flaw in Internet Explorer that can enable hackers to steal your cookies. This exploit is being referred to as “cookiejacking” and apparently is possible in any version of Internet Explorer under any version of Windows.

Valotta claims that in order to exploit the vulnerability, the hacker must drag and drop an object across the PC for the cookie to be stolen. For example, a Facebook page that requires people to drag and drop an object by undressing an onscreen photo of a woman. This allows the hacker to capture the user’s Facebook credentials via a cookie.

“I published this game online on Facebook and in less than three days, more than 80 cookies were sent to my server. And I’ve only got 150 friends,” said Valotta.

“Given the level of required user interaction, this issue is not one we consider high risk in the way a remote code execution would possibly be to users. In order to possibly be impacted a user must visit a malicious Web site, be convinced to click and drag items around the page and the attacker would need to target a cookie from the Web site that the user was already logged into. We encourage all customers to protect themselves against potential issues by avoiding clicking on suspicious links and e-mails, as well as adjusting Internet settings to higher security levels,” said Microsoft spokesman Jerry Bryant.

Microsoft, however, doesn’t seem to see a real-world risk to “cookiejacking.”

Share This Post:

Share this article:
Tags:
Internet Explorer Security
Previous Article Citrix Announces GoToManage Monitoring for XenServer – onmsft.com Next Article Infographic: Skype Goes From Rags to Microsoft – onmsft.com

Related Articles

Chrome’s Organizer feature may sync Gemini and AI conversations across devices

March 14, 2026

After Chrome, Edge tests launching the browser automatically when you sign into Windows

March 13, 2026
Latest iPhone Fold rumors reveal display crease details, hole-punch cameras, iOS multitasking layout, 12GB RAM, and storage options for Apple’s first foldable iPhone.

iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed

March 13, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge
  • Elon Musk’s X to Change Verification in Europe Following EU Fine

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge
  • Elon Musk’s X to Change Verification in Europe Following EU Fine

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy