Archive for the 'Session' Category

Session Fixation

Saturday, May 3rd, 2008

A very trendy attack that targets sessions is session fixation . The most important reason behind its popularity is that it’s the easiest method by which an aggressor can obtain a valid session identifier. As such, its intended use is as a way in to a session hijacking attack, impersonating a user by presenting the [...]