Blog, Netsparker Blog
Understanding session fixation attacks | Netsparker
Understanding session fixation attacks

This article was originally published by LOGON’s partner Invicti.
Session fixation is a web-based attack technique where an attacker tricks the user into opening a URL with a predefined session identifier. Session fixation attacks can allow the attacker to take over a victim’s session to steal confidential data, transfer funds, or completely take over a user account. Learn why session fixation is possible and how to prevent it.
Comments are closed