← Back to Attack / Defense Lab
OSI LAYER 5 // Session Layer

Session Hijacking

Session hijacking is unauthorized use of a valid session identifier or token to impersonate the authenticated user.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

The attacker obtains or influences a session token and then presents it to the service. Theft can result from insecure transport, XSS, malware, logs, or endpoint compromise.

02 // DETECTION

Indicators to watch

Concurrent sessions from unusual locations, token reuse patterns, sudden device changes, and session use inconsistent with the user’s normal behavior.

03 // ATTACK FLOW

Concept diagram

01Valid session↓
02Token exposure↓
03Token reused by attacker↓
04User impersonation↓
05Secure cookies + rotation
04 // PREVENTION

Defensive controls

Use HTTPS, secure/HttpOnly/SameSite cookies, short-lived tokens, session rotation, revocation, device/risk signals, and never log secrets.

05 // SECURITY TOOL

Recommended security control

Identity provider session monitoring

Demonstrate with synthetic sessions in a local lab.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.