Session Hijacking
An attack where an attacker steals or predicts a valid session token to impersonate an authenticated user without knowing their password.
Session hijacking occurs when an attacker obtains a valid session token, the identifier that proves a user is authenticated. With this token, the attacker can impersonate the user without knowing their password. Tokens can be stolen via XSS attacks, network sniffing on unencrypted connections, or malware.
Once hijacked, the attacker has full access to the victim’s session until it expires or is invalidated. They can view data, perform actions, and change settings as the authenticated user.
Defenses include using HTTPS everywhere (preventing network sniffing), setting secure and HttpOnly flags on session cookies, implementing session timeout and re-authentication for sensitive actions, and binding sessions to IP addresses or device fingerprints.
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide