3 ms·
What security tools would have prevented this type of session hijacking attack? Cyberark EPM? Hashicorp Vault/Boundary?
by Ashwizard1 3y ago
What security tools would have prevented this type of session hijacking attack? Cyberark EPM? Hashicorp Vault/Boundary?
- baz00 3y agoSecurity person who thinks tools first needs to get clue stick first.
- nonameiguess 3y agoThe company just has to actually care about the security of peripheral systems like this that aren't directly a part of their product offering. Okta has more than sufficiently smart admins who can prevent session tokens from being stolen, but I'm willing to bet their attention is devoted 95% at least to Okta itself and not their external help desk that they probably don't even run themselves. Attackers will always find your weakest link, whatever you think is too insignificant to devote effort to.
- vel0city 3y agoHow about not attaching the session tokens to support tickets for a start?