Replay Attack
A replay attack reuses a previously captured valid message, token, or transaction in a context where freshness should have been required.
Mechanism
The attacker does not need to understand or alter the original message if the protocol accepts it again without adequate freshness or uniqueness checks.
Indicators to watch
Duplicate transaction identifiers, repeated nonces/timestamps, repeated authentication assertions, or identical requests outside expected timing windows.
Concept diagram
Defensive controls
Use nonces, timestamps, sequence numbers, short token lifetimes, challenge-response protocols, and server-side replay detection.
Recommended security control
SIEM correlation + protocol logging
Use synthetic messages and timestamps in a closed lab.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.