Be Careful When You Choose “Remember Me” on Sensitive Websites

Joe Engelking

Ready to Solve Your IT Problems and/or Protect Your Systems?

When you login to a website you will be presented with a convenient choice to “Remember me for XX days”

The problem with this helpful little option is that when you allow the website to perform this action for you, there is now a cookie left on your computer that hackers can steal when you fall for…

Phishing Attacks

You click on that link and think nothing happened but you couldn’t be more WRONG: Attackers use phishing techniques to trick users into clicking on a malicious link or downloading malicious files but in many cases the attacker can compromise the user’s browser and steal cookies, including those helpful “Remember Me” cookies.

Once the attacker has the cookie, they can use it to gain access to the user’s account without needing to know their password because…

Attackers Can Exploit “Remember Me” Cookies for XX days:

  • Step 1: The attacker steals or intercepts the “Remember Me” cookie via XSS, MitM attacks, or another phishing method.
  • Step 2: They then inject the stolen cookie into their browser, at their location and impersonate you.
  • Step 3: If the cookie is valid and the session isn’t invalidated, the attacker now has full access to the user’s account.

This Flaw Gives Hackers Access to Bank Accounts, Investment Portfolios, Email Accounts and Much More

Cybersecurity is no joke and the littlest checkmark could cost your life savings

AWARD-WINNING CYBERSECURITY AND I.T. SERVICES

TOP 10% OF ALL REVIEWED I.T. PROVIDERS
UPCITY TOP REVIEWED I.T. PROVIDER
EXPERTISE CURATED TOP PICK
DESIGNRUSH TOP CHICAGO I.T. PROVIDER
RANKED TOP 5 ON GOODFIRM’S TOP CYBERSECURITY PROVIDERS LIST
National IT & Cybersecurity Coverage
Managed IT Services
System Audits/Assessments
Design & Installation
Software Implementation
Custom Software Development
Remote Monitoring
24/7 On-Call Support
Cybersecurity
ISO Consulting
SOC Consulting
HIPAA Consulting
Systems Monitoring
Policy Development
Fraud Prevention
Data Protection
Tools
Download
Contact
Headquarters
Chicago, Illinois
847-496-5196
Schedule a Free Consultation