Short Name |
HTTP:STC:SCRIPT:COOKIE-BOMB |
---|---|
Severity |
Critical |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Malicious Javascript CookieBomb Attack |
Release Date |
2013/10/07 |
Update Number |
2307 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects a known technique to drop malicious contents via a victim's browser through specially crafted obfuscated JavaScript. The JavaScript looks for specific cookie values and malicious code is only executed once certain conditions are met. This technique is where an attacker will compromise a normally benign website and adds malicious content without the site's owner being aware of it. A successful attack would result in a complete compromise of the viewing user's browser.