wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

Session Vulnerabilities

profile
Akanksha Rathod
Aug 17, 2022
1 Like
0 Discussions
106 Reads

Before we learn about the vulnerabilities we should know what is a session.

You might have observed being logged out from a website after you keep it idle for a long time, you also get a message stating that "Session has expired".

Session simply means a group of interactions that a user has on a website within a given time frame. Visiting a website can also be considered as a session, however, in technical words, session can be captured by existing the website or by a period of user inactivity.

How can a session be vulnerable?


1) Generating weak session management:

The logic of creating a session token is pretty simple. The attacker is able to learn the pattern and is able to create a valid fake token using the exposed logic behind the session token creation.

2) Poor handling of sessions:
If the session is not terminated properly, or the token is leaked within the network, token hijacking can take place, where the attacker can easily invade.

3) Using meaningful token as a session ID:
Some developers tries to put a lot of information in the session ID, these information may include username, user id, email address, etc. The value may be encrypted and look long however, if it is decoded, it will give out all the useful information of the user.

4) Using predictable tokens:
The session ID tokens are in encrypted format and hence, we feel that they are safe. However, we do not know if they consist of some pattern or a sequence that is commonly used, if so, attackers can easily guess the token.

Session cookies puts the data into temporary memory and deletes it once the session is finished. This data is then used to track the user's development throughout the website. If these sessions are not managed properly, user's information can be stolen like passwords or confidential data. This attack is called as session hijacking. Attacker can use brute force, can guess or predict the exposed session tokens and impersonates and hijacks a genuine user. 


Comments ()


Sign in

Read Next

Predictive Analytics: How Data Science Predicts Trends(Weather ,Stock Market,Sales Forecasting ).

Blog banner

CONCURRENCY

Blog banner

The Importance of Financial Literacy for College Students

Blog banner

Practical Implementation of Client Server model using TCP/IP.

Blog banner

Social Engineering Deceptions and Defenses

Blog banner

Data Science in Healthcare: Predicting Diseases

Blog banner

A-B-C of Networking: Part-3 (Topology [Ring, Tree, Mesh])

Blog banner

Product Discount Calculator

Blog banner

Understanding Endometriosis and Its Psychological Impact on Quality of Life

Blog banner

Fudgy Tahini Date Chocolate Bars

Blog banner

Cyber Attacks -- Trends Patterns and Security Countermeasures

Blog banner

Types Of scheduling

Blog banner

From Airboat Tours to Fossil Hunting: The Ultimate Arcadia Travel Experience

Blog banner

(Input/Output) in os

Blog banner

Short note on Microsoft office

Blog banner

Whatsapp Messenger

Blog banner

Modern Operating System - Khush bagaria

Blog banner

Memory Management

Blog banner

Service transition principles

Blog banner

KEAP MANAGEMENT SYSTEM

Blog banner

Raising Emotionally Intelligent Students: The Classroom Beyond Academics

Blog banner

Sage

Blog banner

Memory managment

Blog banner

OLA

Blog banner

Virus

Blog banner

IT Service as as Value Creation

Blog banner

Honeypot in cyber security

Blog banner

Data Warehousing

Blog banner

Hey Aryan here

Blog banner

child Labour

Blog banner

Proton mail

Blog banner

Corporate Discipline.

Blog banner

12 Principles of Animation

Blog banner

RAID_142

Blog banner

How to Run your First android App

Blog banner

DEVELOPMENTS LEADING TO MODERN OPERATING SYSTEMS

Blog banner

A-B-C of Networking: Part-1 (Basics)

Blog banner

Modern Operating System

Blog banner

Article on Fresh Book

Blog banner

Digital marketing spotlight “Dove’s Real Beauty Campaign”

Blog banner

Principal of concurrency

Blog banner

Time Series Analysis

Blog banner