Let's talk about your project

Session hijacking

An attacker stealing a signed-in user's session token or cookie to act as that user without knowing the password.

  1. 01

    Why it matters

    If a session cookie is stolen, the password and even multi-factor authentication have effectively been bypassed, because the sign-in has already happened. Setting cookies so that scripts cannot read them and they are sent only over encrypted connections, limiting session lifetimes and asking for re-authentication for critical actions reduce the risk.

  2. 02

    Example

    Malware on an employee's computer collects the session cookies in the browser. With them the attacker enters the company's cloud account without a password prompt; once the session from a suspicious location is detected, all sessions are revoked.

  3. 03

    Common mistake

    Not ending open sessions when a user signs out or changes their password. If old sessions stay valid, a stolen cookie keeps working even after the password changes.

  4. 04
Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.