Session Fixation
Session fixation occurs when an attacker causes a victim to authenticate using a session identifier that the attacker already knows.
Mechanism
The application accepts a pre-authentication session and fails to issue a new identifier after login or privilege elevation.
Indicators to watch
Authentication events where the session identifier remains unchanged, reuse of pre-login tokens, and suspicious session continuity across privilege changes.
Concept diagram
Defensive controls
Regenerate session identifiers after authentication and privilege changes; invalidate old sessions and use secure cookie attributes.
Recommended security control
Web framework session management
Use a local test application to verify session rotation.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.