← Back to Attack / Defense Lab
OSI LAYER 5 // Session Layer

Session Fixation

Session fixation occurs when an attacker causes a victim to authenticate using a session identifier that the attacker already knows.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

The application accepts a pre-authentication session and fails to issue a new identifier after login or privilege elevation.

02 // DETECTION

Indicators to watch

Authentication events where the session identifier remains unchanged, reuse of pre-login tokens, and suspicious session continuity across privilege changes.

03 // ATTACK FLOW

Concept diagram

01Pre-login session↓
02Attacker-known identifier↓
03Victim authenticates↓
04Session remains predictable↓
05Rotate ID after login
04 // PREVENTION

Defensive controls

Regenerate session identifiers after authentication and privilege changes; invalidate old sessions and use secure cookie attributes.

05 // SECURITY TOOL

Recommended security control

Web framework session management

Use a local test application to verify session rotation.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.