{"id":478998,"date":"2023-08-09T10:01:33","date_gmt":"2023-08-09T10:01:33","guid":{"rendered":""},"modified":"2023-09-05T11:17:57","modified_gmt":"2023-09-05T11:17:57","slug":"sidejacking","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/cn\/wiki\/sidejacking\/","title":{"rendered":"\u4fa7\u52ab\u6301"},"content":{"rendered":"<p>\u5173\u4e8e Sidejacking \u7684\u7b80\u8981\u4fe1\u606f<\/p>\n<p>\u4fa7\u52ab\u6301\uff0c\u4e5f\u79f0\u4e3a\u4f1a\u8bdd\u52ab\u6301\u6216\u4f1a\u8bdd\u4fa7\u52ab\u6301\uff0c\u662f\u6307\u63a5\u7ba1\u7528\u6237\u7684 Web \u4f1a\u8bdd\u4ee5\u83b7\u53d6\u5bf9\u53d7\u4fdd\u62a4 Web \u8d44\u6e90\u7684\u672a\u7ecf\u6388\u6743\u7684\u8bbf\u95ee\u6743\u9650\u7684\u6076\u610f\u884c\u4e3a\u3002\u653b\u51fb\u8005\u62e6\u622a\u6216\u201c\u52ab\u6301\u201d\u4f1a\u8bdd\u5bc6\u94a5\u6216\u4ee4\u724c\uff0c\u4f7f\u4ed6\u4eec\u80fd\u591f\u5192\u5145\u53d7\u5bb3\u8005\u5e76\u4ee3\u8868\u4ed6\u4eec\u6267\u884c\u64cd\u4f5c\u3002<\/p>\n<h2>Sidejacking \u7684\u8d77\u6e90\u548c\u9996\u6b21\u63d0\u53ca<\/h2>\n<p>\u4fa7\u52ab\u6301\u7684\u8d77\u6e90\u53ef\u4ee5\u8ffd\u6eaf\u5230\u4e92\u8054\u7f51\u53d1\u5c55\u7684\u65e9\u671f\uff0c\u90a3\u65f6\u7684\u5b89\u5168\u63aa\u65bd\u8fd8\u6ca1\u6709\u4eca\u5929\u8fd9\u4e48\u4e25\u683c\u3002\u4fa7\u52ab\u6301\u7684\u9996\u6b21\u8bb0\u5f55\u51fa\u73b0\u5728 2007 \u5e74\uff0c\u5f53\u65f6\u4e00\u4f4d\u540d\u53eb\u7f57\u4f2f\u7279\u00b7\u683c\u96f7\u5384\u59c6 (Robert Graham) \u7684\u8ba1\u7b97\u673a\u5b89\u5168\u4e13\u5bb6\u5728\u9ed1\u5e3d\u5927\u4f1a\u4e0a\u6f14\u793a\u4e86\u8fd9\u9879\u6280\u672f\u3002\u4ed6\u7684\u6f14\u8bb2\u5f15\u8d77\u4e86\u4eba\u4eec\u7684\u5173\u6ce8\uff0c\u5e76\u4fc3\u4f7f\u4eba\u4eec\u52a0\u5f3a\u4e86\u5bf9\u6b64\u7c7b\u7f51\u7edc\u653b\u51fb\u7684\u5ba1\u67e5\u548c\u9884\u9632\u63aa\u65bd\u7684\u5236\u5b9a\u3002<\/p>\n<h2>\u5173\u4e8e Sidejacking \u7684\u8be6\u7ec6\u4fe1\u606f\u3002\u5c55\u5f00 Sidejacking \u4e3b\u9898<\/h2>\n<p>\u4fa7\u52ab\u6301\u653b\u51fb\u7684\u76ee\u6807\u662f\u7528\u6237\u7684\u4f1a\u8bdd\u5bc6\u94a5\uff0c\u8fd9\u4e9b\u5bc6\u94a5\u7528\u4e8e\u5728\u6d3b\u52a8\u7f51\u7edc\u4f1a\u8bdd\u671f\u95f4\u5bf9\u7528\u6237\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\u3002\u8fd9\u4e9b\u5bc6\u94a5\u6216 Cookie \u901a\u5e38\u4ee5\u672a\u52a0\u5bc6\u7684\u5f62\u5f0f\u901a\u8fc7 HTTP \u53d1\u9001\uff0c\u56e0\u6b64\u5f88\u5bb9\u6613\u88ab\u62e6\u622a\u3002<\/p>\n<h3>Sidejacking \u6d89\u53ca\u7684\u5173\u952e\u7ec4\u4ef6\uff1a<\/h3>\n<ol>\n<li><strong>\u4f1a\u8bdd\u5bc6\u94a5<\/strong>\uff1a\u5c06\u7528\u6237\u4e0e\u7279\u5b9a\u4f1a\u8bdd\u5173\u8054\u7684\u552f\u4e00\u6807\u8bc6\u7b26\u3002<\/li>\n<li><strong>\u653b\u51fb\u8005<\/strong>\uff1a\u8bd5\u56fe\u52ab\u6301\u4f1a\u8bdd\u7684\u4e2a\u4eba\u6216\u5b9e\u4f53\u3002<\/li>\n<li><strong>\u53d7\u5bb3\u8005<\/strong>\uff1a\u4f1a\u8bdd\u88ab\u52ab\u6301\u7684\u7528\u6237\u3002<\/li>\n<li><strong>\u670d\u52a1\u5668<\/strong>\uff1a\u6258\u7ba1\u4f1a\u8bdd\u7684 Web \u670d\u52a1\u5668\u3002<\/li>\n<\/ol>\n<h2>Sidejacking \u7684\u5185\u90e8\u7ed3\u6784\u3002Sidejacking \u662f\u5982\u4f55\u5de5\u4f5c\u7684<\/h2>\n<ol>\n<li><strong>\u76d1\u63a7\u7f51\u7edc\u6d41\u91cf<\/strong>\uff1a\u653b\u51fb\u8005\u76d1\u89c6\u672a\u52a0\u5bc6\u7684\u7f51\u7edc\u6d41\u91cf\uff0c\u5bfb\u627e\u6d3b\u52a8\u4f1a\u8bdd\u3002<\/li>\n<li><strong>\u62e6\u622a<\/strong>\uff1a\u653b\u51fb\u8005\u5229\u7528Wireshark\u6216\u5176\u4ed6\u6570\u636e\u5305\u55c5\u63a2\u5668\u7b49\u5de5\u5177\u62e6\u622a\u4f1a\u8bdd\u5bc6\u94a5\u3002<\/li>\n<li><strong>\u5192\u5145<\/strong>\uff1a\u653b\u51fb\u8005\u4f7f\u7528\u7a83\u53d6\u7684\u4f1a\u8bdd\u5bc6\u94a5\uff0c\u5192\u5145\u53d7\u5bb3\u8005\uff0c\u672a\u7ecf\u6388\u6743\u8bbf\u95ee\u5176\u5e10\u6237\u6216\u79c1\u4eba\u4fe1\u606f\u3002<\/li>\n<li><strong>\u884c\u52a8<\/strong>\uff1a\u653b\u51fb\u8005\u968f\u540e\u53ef\u80fd\u4f1a\u4ee3\u8868\u53d7\u5bb3\u8005\u6267\u884c\u4e00\u4e9b\u64cd\u4f5c\uff0c\u4f8b\u5982\u8f6c\u8d26\u3001\u66f4\u6539\u5bc6\u7801\u7b49\u3002<\/li>\n<\/ol>\n<h2>Sidejacking \u4e3b\u8981\u7279\u5f81\u5206\u6790<\/h2>\n<ul>\n<li><strong>\u6613\u4e8e\u6267\u884c<\/strong>\uff1a\u5728\u4e0d\u5b89\u5168\u7684 Wi-Fi \u7f51\u7edc\u4e0a\u76f8\u5bf9\u5bb9\u6613\u8fdb\u884c\u3002<\/li>\n<li><strong>\u76ee\u6807\u4f1a\u8bae<\/strong>\uff1a\u7279\u5b9a\u4e8e\u7f51\u7edc\u4f1a\u8bdd\uff1b\u65e0\u6cd5\u5b8c\u5168\u63a7\u5236\u53d7\u5bb3\u8005\u7684\u8bbe\u5907\u3002<\/li>\n<li><strong>\u5bf9\u52a0\u5bc6\u7684\u4f9d\u8d56<\/strong>\uff1a\u4e3b\u8981\u5f71\u54cd\u672a\u52a0\u5bc6\u7684 HTTP \u4f1a\u8bdd\u3002<\/li>\n<\/ul>\n<h2>\u5199\u51fa\u5b58\u5728\u54ea\u4e9b\u7c7b\u578b\u7684 Sidejacking\u3002\u4f7f\u7528\u8868\u683c\u548c\u5217\u8868\u6765\u5199<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u4fa7\u52ab\u6301\u7c7b\u578b<\/th>\n<th>\u63cf\u8ff0<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>HTTP \u4f1a\u8bdd\u52ab\u6301<\/td>\n<td>\u9488\u5bf9\u672a\u52a0\u5bc6\u7684 HTTP \u4f1a\u8bdd\u5bc6\u94a5\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u8de8\u7ad9\u70b9\u811a\u672c (XSS) \u52ab\u6301<\/td>\n<td>\u5229\u7528XSS\u6f0f\u6d1e\u52ab\u6301\u4f1a\u8bdd\u3002<\/td>\n<\/tr>\n<tr>\n<td>TCP \u4f1a\u8bdd\u52ab\u6301<\/td>\n<td>\u4f7f\u7528\u5e8f\u5217\u53f7\u63a5\u7ba1 TCP \u8fde\u63a5\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Sidejacking \u7684\u4f7f\u7528\u65b9\u6cd5\u3001\u4f7f\u7528\u8fc7\u7a0b\u4e2d\u9047\u5230\u7684\u95ee\u9898\u53ca\u89e3\u51b3\u65b9\u6cd5<\/h2>\n<ul>\n<li><strong>\u6b3a\u8bc8\u548c\u8eab\u4efd\u76d7\u7a83\u7684\u7528\u9014<\/strong>\uff1a\u4fa7\u52ab\u6301\u53ef\u88ab\u6076\u610f\u7528\u6765\u5192\u5145\u53d7\u5bb3\u8005\uff0c\u4ece\u800c\u5bfc\u81f4\u6b3a\u8bc8\u6216\u8eab\u4efd\u76d7\u7a83\u3002<\/li>\n<li><strong>\u95ee\u9898\uff1a\u4e0d\u5b89\u5168\u7f51\u7edc\u4e2d\u7684\u6f0f\u6d1e<\/strong>\uff1a\u89e3\u51b3\u65b9\u6848\u5305\u62ec\u4f7f\u7528 HTTPS \u548c\u5b89\u5168\u7684 Wi-Fi \u8fde\u63a5\u3001\u91c7\u7528 VPN \u4ee5\u53ca\u786e\u4fdd Web \u5e94\u7528\u7a0b\u5e8f\u4e0a\u7684\u6b63\u786e\u4f1a\u8bdd\u7ba1\u7406\u3002<\/li>\n<li><strong>\u95ee\u9898\uff1a\u8fc7\u65f6\u7684\u5b89\u5168\u534f\u8bae<\/strong>\uff1a\u89e3\u51b3\u65b9\u6848\u5305\u62ec\u5b9a\u671f\u66f4\u65b0\u548c\u9075\u5b88\u6700\u4f73\u5b89\u5168\u5b9e\u8df5\u3002<\/li>\n<\/ul>\n<h2>\u4e3b\u8981\u7279\u5f81\u4ee5\u53ca\u4e0e\u7c7b\u4f3c\u672f\u8bed\u7684\u5176\u4ed6\u6bd4\u8f83\u4ee5\u8868\u683c\u548c\u5217\u8868\u7684\u5f62\u5f0f<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u5b66\u671f<\/th>\n<th>\u7279\u5f81<\/th>\n<th>\u4e0e\u4fa7\u52ab\u6301\u7684\u6bd4\u8f83<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u4fa7\u52ab\u6301<\/td>\n<td>\u4f1a\u8bdd\u5bc6\u94a5\u52ab\u6301\uff0c\u901a\u5e38\u901a\u8fc7 HTTP<\/td>\n<td>\u2013<\/td>\n<\/tr>\n<tr>\n<td>\u4e2d\u95f4\u4eba\u653b\u51fb<\/td>\n<td>\u62e6\u622a\u548c\u6539\u53d8\u901a\u4fe1<\/td>\n<td>\u6bd4\u4fa7\u52ab\u6301\u66f4\u5e7f\u6cdb\u7684\u653b\u51fb<\/td>\n<\/tr>\n<tr>\n<td>\u7f51\u7edc\u9493\u9c7c<\/td>\n<td>\u6b3a\u9a97\u7528\u6237\u83b7\u53d6\u654f\u611f\u4fe1\u606f<\/td>\n<td>\u65b9\u6cd5\u4e0d\u540c\uff0c\u76ee\u6807\u76f8\u540c<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u4e0e Sidejacking \u76f8\u5173\u7684\u672a\u6765\u89c2\u70b9\u548c\u6280\u672f<\/h2>\n<ul>\n<li><strong>HTTPS \u7684\u4f7f\u7528\u589e\u52a0<\/strong>\uff1a\u5e7f\u6cdb\u91c7\u7528 HTTPS \u5c06\u6700\u5927\u9650\u5ea6\u5730\u964d\u4f4e Sidejacking \u98ce\u9669\u3002<\/li>\n<li><strong>\u4eba\u5de5\u667a\u80fd\u548c\u673a\u5668\u5b66\u4e60<\/strong>\uff1a\u5b9e\u65bd\u4eba\u5de5\u667a\u80fd\u9a71\u52a8\u7684\u5f02\u5e38\u68c0\u6d4b\u4ee5\u8bc6\u522b\u53ef\u7591\u6d3b\u52a8\u3002<\/li>\n<li><strong>\u66f4\u4e25\u683c\u7684\u89c4\u5b9a<\/strong>\uff1a\u52a0\u5f3a\u6cd5\u5f8b\u548c\u76d1\u7ba1\u884c\u52a8\uff0c\u6253\u51fb\u7f51\u7edc\u72af\u7f6a\u3002<\/li>\n<\/ul>\n<h2>\u5982\u4f55\u4f7f\u7528\u4ee3\u7406\u670d\u52a1\u5668\u6216\u5c06\u5176\u4e0e Sidejacking \u5173\u8054<\/h2>\n<p>\u4ee3\u7406\u670d\u52a1\u5668\uff08\u4f8b\u5982 OneProxy \u63d0\u4f9b\u7684\u4ee3\u7406\u670d\u52a1\u5668\uff09\u53ef\u4ee5\u589e\u52a0\u4e00\u5c42\u989d\u5916\u7684\u5b89\u5168\u4fdd\u62a4\uff0c\u4ee5\u9632\u6b62 Sidejacking\u3002\u901a\u8fc7\u52a0\u5bc6\u6d41\u91cf\u5e76\u5c06\u5176\u8def\u7531\u5230\u5b89\u5168\u670d\u52a1\u5668\uff0c\u4ee3\u7406\u53ef\u4ee5\u4fdd\u62a4\u4f1a\u8bdd\u5bc6\u94a5\u514d\u906d\u62e6\u622a\u3002\u6b64\u5916\uff0c\u4f7f\u7528\u4fe1\u8a89\u826f\u597d\u7684\u4ee3\u7406\u670d\u52a1\u5668\u53ef\u786e\u4fdd Web \u6d41\u91cf\u4e0d\u4f1a\u66b4\u9732\u7ed9\u6f5c\u4f0f\u5728\u4e0d\u5b89\u5168\u7f51\u7edc\u4e0a\u7684\u653b\u51fb\u8005\u3002<\/p>\n<h2>\u76f8\u5173\u94fe\u63a5<\/h2>\n<ul>\n<li><a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_new\" rel=\"noopener nofollow\">OWASP \u5341\u4f73\u9879\u76ee<\/a><\/li>\n<li><a href=\"https:\/\/tools.ietf.org\/html\/rfc6265\" target=\"_new\" rel=\"noopener nofollow\">RFC 6265 \u2013 HTTP \u72b6\u6001\u7ba1\u7406\u673a\u5236<\/a><\/li>\n<li><a href=\"https:\/\/oneproxy.pro\/cn\/\" target=\"_new\" rel=\"noopener\">OneProxy\u7f51\u7ad9<\/a> \u7528\u4e8e\u5b89\u5168\u4ee3\u7406\u670d\u52a1\u5668\u89e3\u51b3\u65b9\u6848\u3002<\/li>\n<li><a href=\"https:\/\/attack.mitre.org\/\" target=\"_new\" rel=\"noopener nofollow\">MITRE ATT&amp;CK \u6846\u67b6<\/a> \u4e86\u89e3\u6709\u5173\u7f51\u7edc\u5a01\u80c1\u548c\u9632\u5fa1\u7684\u4fe1\u606f\u3002<\/li>\n<\/ul>","protected":false},"featured_media":478999,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-478998","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Sidejacking<\/mark>","faq_items":[{"question":"What is Sidejacking and how does it work?","answer":"<p>Sidejacking, or session hijacking, is the malicious act of taking over a user's web session to gain unauthorized access to protected resources. It works by monitoring unencrypted network traffic, intercepting the session key, impersonating the victim, and then executing actions on their behalf.<\/p>"},{"question":"What was the first mention of Sidejacking?","answer":"<p>The first mention of Sidejacking was by computer security expert Robert Graham, who demonstrated the technique at the Black Hat conference in 2007. This sparked awareness and led to increased security measures.<\/p>"},{"question":"How can Sidejacking be prevented?","answer":"<p>Preventing Sidejacking can be achieved through using HTTPS for web sessions, secure Wi-Fi connections, employing Virtual Private Networks (VPNs), ensuring proper session management on web applications, and utilizing reputable proxy servers like OneProxy.<\/p>"},{"question":"What types of Sidejacking exist?","answer":"<p>There are several types of Sidejacking, including HTTP Session Hijacking, Cross-Site Scripting (XSS) Hijacking, and TCP Session Hijacking. Each type targets different aspects of network communication and has unique characteristics.<\/p>"},{"question":"How is Sidejacking different from other cyber-attacks like Phishing or Man-in-the-Middle Attacks?","answer":"<p>While Sidejacking focuses specifically on intercepting web session keys, Phishing deceives users to gain sensitive information, and Man-in-the-Middle Attacks involve intercepting and altering communication between two parties. Sidejacking is more specific in its approach, whereas the others have broader applications.<\/p>"},{"question":"What are the future perspectives and technologies related to Sidejacking?","answer":"<p>The future perspectives include increased adoption of HTTPS, AI-driven anomaly detection, stricter regulations, and more robust security practices. These technologies and strategies will contribute to minimizing Sidejacking risks.<\/p>"},{"question":"How can proxy servers like those provided by OneProxy be associated with Sidejacking?","answer":"<p>Proxy servers from providers like OneProxy add an extra layer of security against Sidejacking. By encrypting traffic and routing it through a secure server, proxies shield session keys from potential interception and reduce the risk of attack on unsecured networks.<\/p>"},{"question":"Where can I find more information and resources about Sidejacking?","answer":"<p>You can find more detailed information on Sidejacking through resources like the <a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_new\">OWASP Top Ten Project<\/a>, <a href=\"https:\/\/tools.ietf.org\/html\/rfc6265\" target=\"_new\">RFC 6265 - HTTP State Management Mechanism<\/a>, the <a href=\"https:\/\/oneproxy.pro\" target=\"_new\">OneProxy Website<\/a>, and the <a href=\"https:\/\/attack.mitre.org\/\" target=\"_new\">MITRE ATT&amp;CK Framework<\/a>.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki\/478998","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki\/478998\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/media\/478999"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/media?parent=478998"}],"curies":[{"name":"\u53ef\u6e7f\u6027\u7c89\u5242","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}