CookieMonster: Automated Session Hijacking Archival and Analysis
Joshua James Pauli, Patrick Henry Engebretson, Michael Ham, MarcCharles J. Zautke · 2011
We introduce a process-driven experiment named "CookieMonster" that can be ran against any cookie granting (i.e. session identification generation) application to test for strength of the cookie generation algorithm. The Cookie Monster processes are applicable to any operating system, web server, and web application as long as session identifiers are granted to requesting client machines. Our goal is to decipher how likely session hijacking attacks may be successful strictly because of weak session identifier generation by the web application. These processes and necessary infrastructure setup can be followed for future generations of web application and web server products because of the universal approach we created. Setup for the experiment includes a web server running a web application that grants session identifiers (cookies), an attack machine running our rapid request software (Bockscar) and a database for archival and analysis of the cookies.