166 terms · 75/46/45
kompozit · edukator režim · za predavanje i PDF

Token Theft

Pretnja u centru, tehnike kojima se izvodi levo, odbrane koje je suzbijaju desno. Ispod — mapa faza napada: kojom tehnikom se ulazi i koja odbrana je presreće.

↘ Techniques used to carry it out6

threat · № 018 · identity

Token Theft

A token is proof that you have already logged in. When you sign in and confirm your identity with a second factor, the service issues a token, stored in the browser, which vouches that you have already been checked the next time round. The token is sent automatically with every further request, so you do not have to type the password again. Token theft is the taking of that proof. With it in hand, the attacker presents themselves as you — without your password and without the second factor, because both have already been approved.

↓ izvor: prvi po vezama Najčešći ulaz: Credential Abuse. Ključna odbrana: Logging & Monitoring.

↗ How it is defended against5