Session hijacking
An attacker stealing a signed-in user's session token or cookie to act as that user without knowing the password.
- 01
Why it matters
If a session cookie is stolen, the password and even multi-factor authentication have effectively been bypassed, because the sign-in has already happened. Setting cookies so that scripts cannot read them and they are sent only over encrypted connections, limiting session lifetimes and asking for re-authentication for critical actions reduce the risk.
- 02
Example
Malware on an employee's computer collects the session cookies in the browser. With them the attacker enters the company's cloud account without a password prompt; once the session from a suspicious location is detected, all sessions are revoked.
- 03
Common mistake
Not ending open sessions when a user signs out or changes their password. If old sessions stay valid, a stolen cookie keeps working even after the password changes.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.