wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

Session Vulnerabilities

profile
Akanksha Rathod
Aug 17, 2022
1 Like
0 Discussions
104 Reads

Before we learn about the vulnerabilities we should know what is a session.

You might have observed being logged out from a website after you keep it idle for a long time, you also get a message stating that "Session has expired".

Session simply means a group of interactions that a user has on a website within a given time frame. Visiting a website can also be considered as a session, however, in technical words, session can be captured by existing the website or by a period of user inactivity.

How can a session be vulnerable?


1) Generating weak session management:

The logic of creating a session token is pretty simple. The attacker is able to learn the pattern and is able to create a valid fake token using the exposed logic behind the session token creation.

2) Poor handling of sessions:
If the session is not terminated properly, or the token is leaked within the network, token hijacking can take place, where the attacker can easily invade.

3) Using meaningful token as a session ID:
Some developers tries to put a lot of information in the session ID, these information may include username, user id, email address, etc. The value may be encrypted and look long however, if it is decoded, it will give out all the useful information of the user.

4) Using predictable tokens:
The session ID tokens are in encrypted format and hence, we feel that they are safe. However, we do not know if they consist of some pattern or a sequence that is commonly used, if so, attackers can easily guess the token.

Session cookies puts the data into temporary memory and deletes it once the session is finished. This data is then used to track the user's development throughout the website. If these sessions are not managed properly, user's information can be stolen like passwords or confidential data. This attack is called as session hijacking. Attacker can use brute force, can guess or predict the exposed session tokens and impersonates and hijacks a genuine user. 


Comments ()


Sign in

Read Next

Respondo Launches Revolutionary Video Discussion App

Blog banner

Education: Key to your Prosperity

Blog banner

Multicore CPUs

Blog banner

CYBER FORENCIS: PAST, PRESENT AND FUTURE.

Blog banner

Zero Trust Security Model: Revolutionizing Cybersecurity in the Digital Age

Blog banner

Modern Operating System

Blog banner

Earth with no trees

Blog banner

A small world of Sockets

Blog banner

Socket Programming in Java

Blog banner

Memory Management

Blog banner

Security Issues

Blog banner

Fitness regime by Deepesh

Blog banner

Data-Driven Prediction of Virtual Item Prices in Online Games

Blog banner

What is OS Fingerprinting?

Blog banner

Memory Management

Blog banner

Memory Management

Blog banner

**THE MUJAWARR: Transforming the Logistics Industry**

Blog banner

Pro-Tips On How To Keep your Foot Healthy

Blog banner

Fault tolerance

Blog banner

Why Soft Skills Matter as Much as Grades?

Blog banner

Demystifying Cryptography: A Beginner's Guide

Blog banner

Kafka - A Framework

Blog banner

Random Forests

Blog banner

Esri India launches Policy Maps.

Blog banner

How to tie a Tie

Blog banner

OPERATING SYSTEM OBJECTIVES AND FAULT TOLERENCE.

Blog banner

Pandas Matrix Applications

Blog banner

Telegram and it's features

Blog banner

Types of OS

Blog banner

Biometric Authentication and Privacy: Balancing Ethical Concerns

Blog banner

Artical on FreshBooks

Blog banner

Message Passing in OS

Blog banner

Elements and Principles of Photography

Blog banner

What is E-commerce

Blog banner

Operating system

Blog banner

Memory Management

Blog banner

Introduction to Data Science: Life Cycle & Applications

Blog banner

Sleep Matters: The Science Behind Toddler Naps

Blog banner

Lucidchart

Blog banner

Deadlock in operating system

Blog banner

Social media

Blog banner

MODERN OPERATING SYSTEM

Blog banner