# Internet Security #### Internet Treat Models - Different to other treat models: - The attacker isn’t in control of the network - The attacker hasn’t got access to the target’s OS ## Cookies - `HTTP` is a **stateless** protocol - Most of what we do online is **stateful** - Cookies are small text files used to provide *persistence* - Servers can provide cookies during HTTP responses, using `Set-Cookie` - Browsers will return any cookies for a given domain in `GET` and `POST` requests ![1647531804.png](img/1647531804.png) ### Types of Cookie - **Session** - Deleted when the browser exits, contain no expiration date - **Persistent** - Expire at a given time - **Secure** - Can only be used over `HTTPS` - `HTTPOnly` - Inaccessible to `js` - Makes it harder to steal ##### Third Party Cookies - Cookies are associated with the domains that produced them - `amazon.com` cookies don’t go to `google.com` - Some websites include request to other domains, such as 3rd party advertisers - These serve cookies *a lot* - This is how advertiser companies know what ads you’ve been served and what adverts you’ve clicked on ### Cookie Vulnerabilities - How a website uses a cookies is up to the server - Many create a `SID` to authenticate users, for example to *keep me logged on* - Obtaining this cookie - *cookie stealing* - lets you **hijack** their session - `HTTP` Cookies can be stolen simply by monitoring - `HTTPS` will require cross-site scripting attacks or DNS poisoning #### Cross-site Scripting (XSS) - A type of *injection attack*, similar in many ways to an SQL injection - HTML is read by a browser and is a combination of content and structure - If we can inject `html` structures into the content of a website, the browser will simply execute these - e.g. a `