Chrome DevTools를 이용한 인증 세션 탈취 기술이 공개되었습니다.
사이버 보안 연구원들이 Chrome DevTools Protocol(CDP)을 활용하여 실행 중인 Google Chrome 또는 Microsoft Edge에서 인증된 세션을 탈취하는 기술을 자세히 설명했습니다. 이 기법은 이미 Windows 호스트에서 코드 실행 권한을 가진 공격자가 사용할 수 있으며, 쿠키 및 저장된 데이터에 접근할 수 있는 방법을 제공합니다.
A technique using Chrome DevTools for authenticated session hijacking has been revealed.
Cybersecurity researchers have detailed a technique that utilizes the Chrome DevTools Protocol (CDP) to hijack authenticated sessions in live instances of Google Chrome or Microsoft Edge on Windows. This technique assumes the attacker already has code execution on the Windows host, allowing access to cookies and saved data.