Mojira Archive
WEB-441

Cookie stealing from mojang.com and minecraft.net with fix instructions

As I heard that hackers called ourmine can steal everyone's account by stealing cookies, I checked session cookies of mojang.com and minecraft.net. I found the reason of vulnerability:
Session cookies are not set to httpOnly nor isSecure. Those flags should be set to true to prevent stealing cookies.

For bugs.mojang.com its "httponly", but without "issecure". Please add "issecure" also for bugs.mojang.com session cookie.

Fixed

[Helper] MichaƂ

[Mojang] Web Team

2016-07-21, 07:49 PM

2017-02-20, 09:42 AM

2017-02-20, 09:42 AM

0

1