15–25 min Updated

Session Fixation

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

Insecure treatment of session IDs can leave your users vulnerable to having their session hijacked.

Prevalence
Rare
Exploitability
Moderate
Impact
Harmful

What is session fixation?

Session fixation is a session hijacking attack in which an attacker chooses a session ID and tricks a victim into logging in with it, often by sending a link containing the ID. If the application keeps the same session ID after login, the attacker can use it to access the victim's account as that authenticated user.

What you'll learn

  • How an attacker plants a session ID they already know on a victim
  • Why session IDs do not belong in the query string
  • Why the session ID must be regenerated when a user logs in

Where this lesson counts

OWASP Top 10

  • Session Fixation lab

    Your site accepts session IDs in the query string. Follow Mal as he picks a session ID, puts it in a link to a hamster gif and emails it to Vic. Vic logs in, and Mal opens the same URL to find himself inside Vic's account.

  • How to prevent Session Fixation

    The prevention guide covers six approaches:

    • Don't Pass Session IDs in GET/POST Variables
    • Regenerate the Session ID at Authentication
    • Accept Only Server-Generated Session IDs
    • Timeout and Replace Old Session IDs
    • Implement a Strong Logout Function
    • Require a New Session When Visiting From Suspicious Referrers
  • Session Fixation quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Weak Session IDs

    Guessable session IDs make your website vulnerable to session hijacking.

  • Cross-Site Request Forgery

    If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.

  • Password Mismanagement

    Safe treatment of passwords is essential to a secure authentication system - yet many websites get this wrong.

  • Cross-Site Scripting

    If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.