Session Hijacking
Session hijacking is unauthorized use of a valid session identifier or token to impersonate the authenticated user.
Mechanism
The attacker obtains or influences a session token and then presents it to the service. Theft can result from insecure transport, XSS, malware, logs, or endpoint compromise.
Indicators to watch
Concurrent sessions from unusual locations, token reuse patterns, sudden device changes, and session use inconsistent with the user’s normal behavior.
Concept diagram
Defensive controls
Use HTTPS, secure/HttpOnly/SameSite cookies, short-lived tokens, session rotation, revocation, device/risk signals, and never log secrets.
Recommended security control
Identity provider session monitoring
Demonstrate with synthetic sessions in a local lab.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.