Lesson:
Weak Session IDs
Public previewWant everyone on your software team to learn this? Get completion tracking and compliance reporting with Hacksplaining for Teams. Free 14-day trial.
Train my teamMal plugs one of these IDs into his browser, and voila, he has hijacked somebody's session.

Headers
▼ General
Remote Address: 121.232.112.200:443
Request Method: GET
Status Code: 200 OK
▶ Request Headers
▼ Response Headers
Set-Cookie: session_id=41293