Refers to an attack where an attacker takes over a valid TCP communication session between two computers.
Session Hijacking
Session Hijacking Concepts:
b. Spoofing Attack
Session Hijacking Concepts:
a. Hijacking
Application Level Session Hijacking:
Cross-Site Request Forgery (CSRF)
Application Level Session Hijacking:
When a website acquires your credentials (Username & Password)
Cross-Site Scripting (XSS)
Network Level Session Hijacking:
b. Blind Hijacking
An attacker relies on the legitimate user to connect and authenticate and will then take over the session.
Session Hijacking
The attacker pretends to be another user or machine to gain access.
Spoofing Attack