Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. IE Security Flaw Exposes Your Cookies – onmsft.com

IE Security Flaw Exposes Your Cookies – onmsft.com

Ron Ron
May 27, 2011
2 min read

Rosario Valotta, a security researcher from Italy, has discovered a flaw in Internet Explorer that could enable hackers to steal cookies from a user’s PC and then use those cookies to log onto password-protected websites.

As cNet reports, A security researcher from Italy discovered this flaw in Internet Explorer that can enable hackers to steal your cookies. This exploit is being referred to as “cookiejacking” and apparently is possible in any version of Internet Explorer under any version of Windows.

Valotta claims that in order to exploit the vulnerability, the hacker must drag and drop an object across the PC for the cookie to be stolen. For example, a Facebook page that requires people to drag and drop an object by undressing an onscreen photo of a woman. This allows the hacker to capture the user’s Facebook credentials via a cookie.

“I published this game online on Facebook and in less than three days, more than 80 cookies were sent to my server. And I’ve only got 150 friends,” said Valotta.

“Given the level of required user interaction, this issue is not one we consider high risk in the way a remote code execution would possibly be to users. In order to possibly be impacted a user must visit a malicious Web site, be convinced to click and drag items around the page and the attacker would need to target a cookie from the Web site that the user was already logged into. We encourage all customers to protect themselves against potential issues by avoiding clicking on suspicious links and e-mails, as well as adjusting Internet settings to higher security levels,” said Microsoft spokesman Jerry Bryant.

Microsoft, however, doesn’t seem to see a real-world risk to “cookiejacking.”

Share This Post:

Share this article:
Tags:
Internet Explorer Security
Previous Article Citrix Announces GoToManage Monitoring for XenServer – onmsft.com Next Article Infographic: Skype Goes From Rags to Microsoft – onmsft.com

Related Articles

PlayStation 6 Price Could Hit $699 Despite Rising Costs, Leak Suggests

PlayStation 6 leaks point to handheld console, lower pricing, and early transition plans

April 3, 2026

TSMC Shifts 4nm Capacity to 3nm as Smartphone Demand Drops and Memory Costs Surge

April 3, 2026

New Uncharted Game Teased as Naughty Dog Director Shares ‘Research’ Photo

April 3, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • PlayStation 6 leaks point to handheld console, lower pricing, and early transition plans
  • TSMC Shifts 4nm Capacity to 3nm as Smartphone Demand Drops and Memory Costs Surge
  • New Uncharted Game Teased as Naughty Dog Director Shares ‘Research’ Photo
  • Intel Bartlett Lake CPU Boots on Z790 After BIOS Trick, Runs Windows Successfully
  • Intel CPU prices set to rise up to 30% in 2026 as AI demand reshapes supply

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • PlayStation 6 leaks point to handheld console, lower pricing, and early transition plans
  • TSMC Shifts 4nm Capacity to 3nm as Smartphone Demand Drops and Memory Costs Surge
  • New Uncharted Game Teased as Naughty Dog Director Shares ‘Research’ Photo
  • Intel Bartlett Lake CPU Boots on Z790 After BIOS Trick, Runs Windows Successfully
  • Intel CPU prices set to rise up to 30% in 2026 as AI demand reshapes supply

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy