← Back to Attack / Defense Lab
OSI LAYER 5 // Session Layer

Replay Attack

A replay attack reuses a previously captured valid message, token, or transaction in a context where freshness should have been required.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

The attacker does not need to understand or alter the original message if the protocol accepts it again without adequate freshness or uniqueness checks.

02 // DETECTION

Indicators to watch

Duplicate transaction identifiers, repeated nonces/timestamps, repeated authentication assertions, or identical requests outside expected timing windows.

03 // ATTACK FLOW

Concept diagram

01Valid message↓
02Captured token / transaction↓
03Message reused later↓
04Duplicate action↓
05Nonce + freshness checks
04 // PREVENTION

Defensive controls

Use nonces, timestamps, sequence numbers, short token lifetimes, challenge-response protocols, and server-side replay detection.

05 // SECURITY TOOL

Recommended security control

SIEM correlation + protocol logging

Use synthetic messages and timestamps in a closed lab.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.