Skip to content

Latest commit

 

History

History
9 lines (8 loc) · 263 Bytes

File metadata and controls

9 lines (8 loc) · 263 Bytes

10 – Session Hijacking

  • Taking control of a valid user session
  • Techniques:
    • Session sniffing
    • Cross-site scripting (XSS)
    • Predicting session tokens
  • Tools: Burp Suite, Ettercap
  • Mitigation: Secure cookies, HTTPS, regenerating session IDs