Session Fixation
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
Insecure treatment of session IDs can leave your users vulnerable to having their session hijacked.
- Prevalence
- Rare
- Exploitability
- Moderate
- Impact
- Harmful
What is session fixation?
Session fixation is a session hijacking attack in which an attacker chooses a session ID and tricks a victim into logging in with it, often by sending a link containing the ID. If the application keeps the same session ID after login, the attacker can use it to access the victim's account as that authenticated user.
What you'll learn
- How an attacker plants a session ID they already know on a victim
- Why session IDs do not belong in the query string
- Why the session ID must be regenerated when a user logs in
Where this lesson counts
OWASP Top 10
Weak passwords, guessable sessions and leaky login flows let attackers assume other identities.
Learn more about A07This lesson includes
-
Session Fixation lab
Your site accepts session IDs in the query string. Follow Mal as he picks a session ID, puts it in a link to a hamster gif and emails it to Vic. Vic logs in, and Mal opens the same URL to find himself inside Vic's account.
-
How to prevent Session Fixation
The prevention guide covers six approaches:
- Don't Pass Session IDs in GET/POST Variables
- Regenerate the Session ID at Authentication
- Accept Only Server-Generated Session IDs
- Timeout and Replace Old Session IDs
- Implement a Strong Logout Function
- Require a New Session When Visiting From Suspicious Referrers
-
Session Fixation quiz
Three questions. Passing marks the lesson complete.
Sources
- Ruby on Rails Security Guide Rails Guides
- ASP.NET Session State Overview Microsoft
- Sessions in Java Oracle
Related lessons
Browse all 45 lessons
Weak Session IDs
Guessable session IDs make your website vulnerable to session hijacking.
Cross-Site Request Forgery
If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.
Password Mismanagement
Safe treatment of passwords is essential to a secure authentication system - yet many websites get this wrong.
Cross-Site Scripting
If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.