wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

Session Vulnerabilities

profile
Akanksha Rathod
Aug 17, 2022
1 Like
0 Discussions
105 Reads

Before we learn about the vulnerabilities we should know what is a session.

You might have observed being logged out from a website after you keep it idle for a long time, you also get a message stating that "Session has expired".

Session simply means a group of interactions that a user has on a website within a given time frame. Visiting a website can also be considered as a session, however, in technical words, session can be captured by existing the website or by a period of user inactivity.

How can a session be vulnerable?


1) Generating weak session management:

The logic of creating a session token is pretty simple. The attacker is able to learn the pattern and is able to create a valid fake token using the exposed logic behind the session token creation.

2) Poor handling of sessions:
If the session is not terminated properly, or the token is leaked within the network, token hijacking can take place, where the attacker can easily invade.

3) Using meaningful token as a session ID:
Some developers tries to put a lot of information in the session ID, these information may include username, user id, email address, etc. The value may be encrypted and look long however, if it is decoded, it will give out all the useful information of the user.

4) Using predictable tokens:
The session ID tokens are in encrypted format and hence, we feel that they are safe. However, we do not know if they consist of some pattern or a sequence that is commonly used, if so, attackers can easily guess the token.

Session cookies puts the data into temporary memory and deletes it once the session is finished. This data is then used to track the user's development throughout the website. If these sessions are not managed properly, user's information can be stolen like passwords or confidential data. This attack is called as session hijacking. Attacker can use brute force, can guess or predict the exposed session tokens and impersonates and hijacks a genuine user. 


Comments ()


Sign in

Read Next

The Future of Cybersecurity: Trends, Challenges, and Strategies

Blog banner

EFT

Blog banner

Veg/Non-veg/Egg Tiffin Meals That Are Nutritious and Filling

Blog banner

Mumbaicha Dabbawalla

Blog banner

Emotional Intelligence in Children: Why It Is as Important as Academics

Blog banner

Operating system

Blog banner

Virus

Blog banner

Different memory allocation strategies

Blog banner

Why Is Freshly Cooked Food Better Than Processed Food for Everyday Health?

Blog banner

Article on team management software

Blog banner

What is 'Multi-core and Multi-threading' ?

Blog banner

Precision-Recall in Data Science

Blog banner

Sleep Matters: The Science Behind Toddler Naps

Blog banner

Software

Blog banner

Disk cache

Blog banner

I/O Management and Disk Scheduling

Blog banner

INTERNET SECURITY

Blog banner

Define Instagram.

Blog banner

c

Blog banner

WomenEmpowerment

Blog banner

MQTT (MQ Telemetry Transport) in Data Science

Blog banner

How to Encrypt and Decrypt Using GNU PGP

Blog banner

Firewall / IDS Evasion Techniques

Blog banner

Evolution of OS

Blog banner

Making Money through Instagram

Blog banner

What is Packet Filtering?

Blog banner

BIRYANI ! The history you never knew about

Blog banner

How to Grow Your Brand on YouTube Without a Big Budget

Blog banner

Direct memory access (DMA)

Blog banner

Digital Balance: Keeping Children Mindful in the Screen Age

Blog banner

S-Tool : Steganography

Blog banner

Memory Management

Blog banner

Multiprocessor and Multicore Organization

Blog banner

Phishing

Blog banner

File Management system

Blog banner

PHISHING

Blog banner

A-B-C of Networking: Part-2 (Components)

Blog banner

virtual machine

Blog banner

VIRTUAL MACHINE

Blog banner

Understanding Loneliness: Why We Feel Disconnected in a Connected World (Part -1)

Blog banner

Power of words

Blog banner

Operating System Objectives and Functions

Blog banner